Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

After the 2017 Equifax Breach, Federal Agencies Looked Beyond One Credit Bureau

After Equifax’s 2017 breach, agencies reportedly contacted Experian and TransUnion to assess whether shared Apache Struts software posed wider industry risk.
From TheFinanceBase Team2 min to read

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

After Equifax disclosed a major 2017 breach, federal agencies reportedly contacted its two largest competitors, Experian and TransUnion, to assess whether shared software could expose the wider credit-reporting industry. The outreach was a separate concern from the law-enforcement investigation into how attackers entered Equifax—and the contemporaneous report did not establish whether either competitor had an unpatched system or was breached.

What did the government do after the Equifax breach?

In a September 14, 2017 report, CyberScoop reporter Chris Bing said federal agencies contacted Equifax competitors to understand whether the breach pointed to broader cyberattack risks. An unnamed senior federal official told CyberScoop that officials reached out because the companies used some of the same programs: “Because they all sort of use these same programs, we needed to contact them too,” the official said. “It’s necessary.”

The report described two related but distinct tracks: federal law enforcement was investigating how and why attackers breached Equifax, while the Department of Homeland Security (DHS) was focused on potential industry-wide risk. The account does not provide a detailed agency plan or later investigation results. CyberScoop’s September 14, 2017 report attributed its description of the outreach to the unnamed official.

Why were Experian and TransUnion contacted?

The report named Experian and TransUnion as Equifax’s competitors and said shared use of Apache Struts was the reason officials contacted them. Apache Struts is software; the concern was whether systems using it could present similar exposure. The report said it was unclear whether or when the competitors had updated systems that might have been running older versions.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That uncertainty matters: the article did not establish that Experian or TransUnion had the same exploitable configuration as Equifax, failed to apply a patch, or suffered a breach. It also reported that the companies did not respond to requests for comment about their communications with government officials.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What was the scale of the Equifax breach?

CyberScoop reported in 2017 that upwards of 143 million records were compromised at Equifax. That is the figure as reported in the contemporaneous article, not a newly verified count. The report described Equifax as one of three multinational corporations managing consumers’ credit reports and other sensitive records, which helps explain why officials were concerned about risk beyond a single company.

What this report does—and does not—show

  • It shows: According to a senior federal official quoted anonymously by CyberScoop, agencies contacted Experian and TransUnion to assess broader risk associated with shared software.
  • It does not show: Whether either competitor was running a vulnerable configuration, whether either had patched its systems, or whether either experienced an intrusion.
  • It does not establish: Current agency activity or current security conditions at any of the three credit bureaus. It is a contemporaneous news account of reported outreach in September 2017, not an official investigation record.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.