{"id":308,"date":"2017-09-30T23:08:10","date_gmt":"2017-10-01T03:08:10","guid":{"rendered":"https:\/\/www.amp.legal\/blog\/?p=308"},"modified":"2018-01-04T16:19:56","modified_gmt":"2018-01-04T21:19:56","slug":"equifax-breach-affects-millions","status":"publish","type":"post","link":"https:\/\/www.amp.legal\/blog\/equifax-breach-affects-millions\/","title":{"rendered":"Equifax Breach Affects Millions"},"content":{"rendered":"<p>On September 7, Equifax announced a massive cyber breach that affected 143 million consumers.\u00a0The intruders accessed information that includes consumers&#8217; names, addresses, Social Security numbers, birth dates, and driver\u2019s license numbers.<\/p>\n<p>Equifax claims the cause of the breach was a vulnerability in Apache Struts. Many companies use this open-source platform to create Java web applications.<\/p>\n<p>Equifax explained that the hackers exploited the Apache Struts CVE-2017-5638 vulnerability. However,\u00a0in March, NIST announced the vulnerability in its National Vulnerability Database. The Apache Software Foundation <a href=\"https:\/\/blogs.apache.org\/foundation\/entry\/media-alert-the-apache-software\" target=\"_blank\" rel=\"noopener noreferrer\">confirmed<\/a> that Equifax failed to install the patches to fix the vulnerability.<\/p>\n<h3>Legal Actions<\/h3>\n<p>Victims of the breach are already filing lawsuits. The City of San Francisco filed a lawsuit that alleges Equifax violated the <a href=\"https:\/\/www.amp.legal\/data-breach-law-tool\/california\/\" target=\"_blank\" rel=\"noopener noreferrer\">California state breach law<\/a> by not implementing reasonable security measures. San Francisco is seeking millions of dollars in civil penalties and consumer restitution.<\/p>\n<p>So far, court records show that the majority of plaintiffs did not allege they were victims of stolen identity. Most courts require a theft of sensitive personal information to establish standing for a lawsuit. To prevail, plaintiffs will need to present evidence showing they were harmed as a result of the Equifax breach.<\/p>\n<h3><img decoding=\"async\" loading=\"lazy\" class=\"size-medium wp-image-312 alignleft\" style=\"float: left; padding-right: 1em;\" src=\"https:\/\/www.amp.legal\/blog\/wp-content\/uploads\/2017\/09\/Equifax-Credit-255x300.png\" alt=\"\" width=\"255\" height=\"300\" srcset=\"https:\/\/www.amp.legal\/blog\/wp-content\/uploads\/2017\/09\/Equifax-Credit-255x300.png 255w, https:\/\/www.amp.legal\/blog\/wp-content\/uploads\/2017\/09\/Equifax-Credit-360x424.png 360w, https:\/\/www.amp.legal\/blog\/wp-content\/uploads\/2017\/09\/Equifax-Credit-250x294.png 250w, https:\/\/www.amp.legal\/blog\/wp-content\/uploads\/2017\/09\/Equifax-Credit-100x118.png 100w, https:\/\/www.amp.legal\/blog\/wp-content\/uploads\/2017\/09\/Equifax-Credit.png 401w\" sizes=\"(max-width: 255px) 100vw, 255px\" \/>Free Credit Services for Victims<\/h3>\n<p>Equifax is offering the breach victims one year of free credit monitoring services. The enrollment period begins when an affected consumer activates the service.\u00a0The deadline to enroll is\u00a0 January 31, 2018.<\/p>\n<p>Consumers can find out if the breach impacted\u00a0them on <a href=\"https:\/\/www.equifaxsecurity2017.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Equifax\u2019s website<\/a>. To receive an instant answer, each\u00a0consumer\u00a0must provide\u00a0their last name and the last six digits of their Social Security number.<\/p>\n<p>If the breach affected a consumer, the site\u00a0returns a message that says, &#8220;Based on the information provided, we believe that your personal information may have been impacted by this incident.&#8221; At that point, the consumer may\u00a0enroll in\u00a0TrustedID Premier for a complimentary one-year subscription.<\/p>\n<p>TrustedID Premier provides \u201cidentity theft protection and credit file monitoring&#8221; and\u00a0includes 5 offerings:<\/p>\n<ol>\n<li>An Equifax credit report<\/li>\n<li>An Equifax credit report lock<\/li>\n<li>Credit file monitoring with Equifax, Experian, and TransUnion<\/li>\n<li>Social security number monitoring<\/li>\n<li>$1 million dollars of identity theft insurance<\/li>\n<\/ol>\n<h3>Ongoing Investigations<\/h3>\n<p>Equifax&#8217;s massive cybersecurity breach puts a spotlight on its competence as an organization to manage consumer data. Currently, several agencies are investigating the Equifax breach including the FBI, the FTC, the SEC, and most state attorneys generals.<\/p>\n<p>For more information about the Equifax breach, visit these links:<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/equifax-breach-no-excuse\/\" target=\"_blank\" rel=\"noopener noreferrer\">Equifax Officially Has No Excuse<\/a><\/p>\n<p><a href=\"https:\/\/www.cbsnews.com\/news\/equifax-data-breach-lawsuit-by-us-city\/\" target=\"_blank\" rel=\"noopener noreferrer\">Equifax Hit With First Lawsuit by U.S. City Over Data Breach<\/a><\/p>\n<p><a href=\"https:\/\/qz.com\/1073221\/the-hackers-who-broke-into-equifax-exploited-a-nine-year-old-security-flaw\/\" target=\"_blank\" rel=\"noopener noreferrer\">The Hackers Who Broke Into Equifax Exploited a Flaw in Open-Source Server Software<\/a><\/p>\n<p><a href=\"https:\/\/www.cnbc.com\/2017\/09\/22\/do-you-want-to-sue-equifax-over-the-cyberbreach-winning-a-lawsuit-may-not-be-so-easy.html\" target=\"_blank\" rel=\"noopener noreferrer\">Do You Want to Sue Equifax Over the Cyberbreach? Winning a Lawsuit May Not Be So Easy<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>On September 7, Equifax announced a massive cyber breach that affected 143 million consumers.\u00a0The intruders accessed information that includes consumers&#8217; names, addresses, Social Security numbers, birth dates, and driver\u2019s license numbers. Equifax claims the cause [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":375,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[42,32,13,25,41,9],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v21.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Equifax Breach Affects Millions - Cyber Law Blog<\/title>\n<meta name=\"description\" content=\"Cyber Law Blog explores legal topics with technology including privacy law and cybersecurity.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.amp.legal\/blog\/equifax-breach-affects-millions\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Equifax Breach Affects Millions - Cyber Law Blog\" \/>\n<meta property=\"og:description\" content=\"Cyber Law Blog explores legal topics with technology including privacy law and cybersecurity.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.amp.legal\/blog\/equifax-breach-affects-millions\/\" \/>\n<meta property=\"og:site_name\" content=\"Cyber Law Blog\" \/>\n<meta property=\"article:published_time\" content=\"2017-10-01T03:08:10+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2018-01-04T21:19:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.amp.legal\/blog\/wp-content\/uploads\/2017\/10\/Sea-Feather.png\" \/>\n\t<meta property=\"og:image:width\" content=\"900\" \/>\n\t<meta property=\"og:image:height\" content=\"525\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Alice M. Porch, Esq., CIPP\/US, C|EH, Security+\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alice M. Porch, Esq., CIPP\/US, C|EH, Security+\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.amp.legal\/blog\/equifax-breach-affects-millions\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.amp.legal\/blog\/equifax-breach-affects-millions\/\"},\"author\":{\"name\":\"Alice M. Porch, Esq., CIPP\/US, C|EH, Security+\",\"@id\":\"https:\/\/www.amp.legal\/blog\/#\/schema\/person\/2abed582dc9fbf067a8aa30d3e21453f\"},\"headline\":\"Equifax Breach Affects Millions\",\"datePublished\":\"2017-10-01T03:08:10+00:00\",\"dateModified\":\"2018-01-04T21:19:56+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.amp.legal\/blog\/equifax-breach-affects-millions\/\"},\"wordCount\":450,\"publisher\":{\"@id\":\"https:\/\/www.amp.legal\/blog\/#organization\"},\"keywords\":[\"Apache\",\"cyber due diligence\",\"cyber security\",\"data breach\",\"Equifax\",\"state breach laws\"],\"articleSection\":[\"Data Breach Laws\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.amp.legal\/blog\/equifax-breach-affects-millions\/\",\"url\":\"https:\/\/www.amp.legal\/blog\/equifax-breach-affects-millions\/\",\"name\":\"Equifax Breach Affects Millions - Cyber Law Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.amp.legal\/blog\/#website\"},\"datePublished\":\"2017-10-01T03:08:10+00:00\",\"dateModified\":\"2018-01-04T21:19:56+00:00\",\"description\":\"Cyber Law Blog explores legal topics with technology including privacy law and cybersecurity.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.amp.legal\/blog\/equifax-breach-affects-millions\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.amp.legal\/blog\/equifax-breach-affects-millions\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.amp.legal\/blog\/equifax-breach-affects-millions\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.amp.legal\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Equifax Breach Affects Millions\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.amp.legal\/blog\/#website\",\"url\":\"https:\/\/www.amp.legal\/blog\/\",\"name\":\"Cyber Law Blog\",\"description\":\"Exploring technology law in cyberspace\",\"publisher\":{\"@id\":\"https:\/\/www.amp.legal\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.amp.legal\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.amp.legal\/blog\/#organization\",\"name\":\"Alice M. Porch, P.A.\",\"url\":\"https:\/\/www.amp.legal\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.amp.legal\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.amp.legal\/blog\/wp-content\/uploads\/2017\/08\/AMP-Logo.png\",\"contentUrl\":\"https:\/\/www.amp.legal\/blog\/wp-content\/uploads\/2017\/08\/AMP-Logo.png\",\"width\":1104,\"height\":1114,\"caption\":\"Alice M. Porch, P.A.\"},\"image\":{\"@id\":\"https:\/\/www.amp.legal\/blog\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.amp.legal\/blog\/#\/schema\/person\/2abed582dc9fbf067a8aa30d3e21453f\",\"name\":\"Alice M. Porch, Esq., CIPP\/US, C|EH, Security+\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.amp.legal\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/b0913e4ef042f9c502b709824db43e8f?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/b0913e4ef042f9c502b709824db43e8f?s=96&d=mm&r=g\",\"caption\":\"Alice M. Porch, Esq., CIPP\/US, C|EH, Security+\"},\"description\":\"Alice is a member of the Florida Bar, and she focuses on data privacy and cybersecurity compliance. She attended the Warrington College of Business at the University of Florida and earned a Bachelor of Science in Business Administration. After graduating, she earned a Juris Doctor at the Stetson University College of Law. During law school, she served as an Assistant Executive Editor for Stetson Law Review and also as a Staff Editor for Stetson Journal of Advocacy and the Law. She also served as a member of The Florida Bar Journal\/News Editorial Board from 2018-2024. She is currently a member of the Florida Bar Cybersecurity and Privacy Law Substantive Law Committee.\",\"sameAs\":[\"https:\/\/www.aliceporch.com\",\"https:\/\/www.linkedin.com\/in\/alice-m-porch\/\"],\"url\":\"https:\/\/www.amp.legal\/blog\/author\/amplegal\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Equifax Breach Affects Millions - Cyber Law Blog","description":"Cyber Law Blog explores legal topics with technology including privacy law and cybersecurity.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.amp.legal\/blog\/equifax-breach-affects-millions\/","og_locale":"en_US","og_type":"article","og_title":"Equifax Breach Affects Millions - Cyber Law Blog","og_description":"Cyber Law Blog explores legal topics with technology including privacy law and cybersecurity.","og_url":"https:\/\/www.amp.legal\/blog\/equifax-breach-affects-millions\/","og_site_name":"Cyber Law Blog","article_published_time":"2017-10-01T03:08:10+00:00","article_modified_time":"2018-01-04T21:19:56+00:00","og_image":[{"width":900,"height":525,"url":"https:\/\/www.amp.legal\/blog\/wp-content\/uploads\/2017\/10\/Sea-Feather.png","type":"image\/png"}],"author":"Alice M. Porch, Esq., CIPP\/US, C|EH, Security+","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Alice M. Porch, Esq., CIPP\/US, C|EH, Security+","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.amp.legal\/blog\/equifax-breach-affects-millions\/#article","isPartOf":{"@id":"https:\/\/www.amp.legal\/blog\/equifax-breach-affects-millions\/"},"author":{"name":"Alice M. Porch, Esq., CIPP\/US, C|EH, Security+","@id":"https:\/\/www.amp.legal\/blog\/#\/schema\/person\/2abed582dc9fbf067a8aa30d3e21453f"},"headline":"Equifax Breach Affects Millions","datePublished":"2017-10-01T03:08:10+00:00","dateModified":"2018-01-04T21:19:56+00:00","mainEntityOfPage":{"@id":"https:\/\/www.amp.legal\/blog\/equifax-breach-affects-millions\/"},"wordCount":450,"publisher":{"@id":"https:\/\/www.amp.legal\/blog\/#organization"},"keywords":["Apache","cyber due diligence","cyber security","data breach","Equifax","state breach laws"],"articleSection":["Data Breach Laws"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.amp.legal\/blog\/equifax-breach-affects-millions\/","url":"https:\/\/www.amp.legal\/blog\/equifax-breach-affects-millions\/","name":"Equifax Breach Affects Millions - Cyber Law Blog","isPartOf":{"@id":"https:\/\/www.amp.legal\/blog\/#website"},"datePublished":"2017-10-01T03:08:10+00:00","dateModified":"2018-01-04T21:19:56+00:00","description":"Cyber Law Blog explores legal topics with technology including privacy law and cybersecurity.","breadcrumb":{"@id":"https:\/\/www.amp.legal\/blog\/equifax-breach-affects-millions\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.amp.legal\/blog\/equifax-breach-affects-millions\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.amp.legal\/blog\/equifax-breach-affects-millions\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.amp.legal\/blog\/"},{"@type":"ListItem","position":2,"name":"Equifax Breach Affects Millions"}]},{"@type":"WebSite","@id":"https:\/\/www.amp.legal\/blog\/#website","url":"https:\/\/www.amp.legal\/blog\/","name":"Cyber Law Blog","description":"Exploring technology law in cyberspace","publisher":{"@id":"https:\/\/www.amp.legal\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.amp.legal\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.amp.legal\/blog\/#organization","name":"Alice M. Porch, P.A.","url":"https:\/\/www.amp.legal\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.amp.legal\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.amp.legal\/blog\/wp-content\/uploads\/2017\/08\/AMP-Logo.png","contentUrl":"https:\/\/www.amp.legal\/blog\/wp-content\/uploads\/2017\/08\/AMP-Logo.png","width":1104,"height":1114,"caption":"Alice M. Porch, P.A."},"image":{"@id":"https:\/\/www.amp.legal\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.amp.legal\/blog\/#\/schema\/person\/2abed582dc9fbf067a8aa30d3e21453f","name":"Alice M. Porch, Esq., CIPP\/US, C|EH, Security+","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.amp.legal\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/b0913e4ef042f9c502b709824db43e8f?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b0913e4ef042f9c502b709824db43e8f?s=96&d=mm&r=g","caption":"Alice M. Porch, Esq., CIPP\/US, C|EH, Security+"},"description":"Alice is a member of the Florida Bar, and she focuses on data privacy and cybersecurity compliance. She attended the Warrington College of Business at the University of Florida and earned a Bachelor of Science in Business Administration. After graduating, she earned a Juris Doctor at the Stetson University College of Law. During law school, she served as an Assistant Executive Editor for Stetson Law Review and also as a Staff Editor for Stetson Journal of Advocacy and the Law. She also served as a member of The Florida Bar Journal\/News Editorial Board from 2018-2024. She is currently a member of the Florida Bar Cybersecurity and Privacy Law Substantive Law Committee.","sameAs":["https:\/\/www.aliceporch.com","https:\/\/www.linkedin.com\/in\/alice-m-porch\/"],"url":"https:\/\/www.amp.legal\/blog\/author\/amplegal\/"}]}},"_links":{"self":[{"href":"https:\/\/www.amp.legal\/blog\/wp-json\/wp\/v2\/posts\/308"}],"collection":[{"href":"https:\/\/www.amp.legal\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.amp.legal\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.amp.legal\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.amp.legal\/blog\/wp-json\/wp\/v2\/comments?post=308"}],"version-history":[{"count":15,"href":"https:\/\/www.amp.legal\/blog\/wp-json\/wp\/v2\/posts\/308\/revisions"}],"predecessor-version":[{"id":341,"href":"https:\/\/www.amp.legal\/blog\/wp-json\/wp\/v2\/posts\/308\/revisions\/341"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.amp.legal\/blog\/wp-json\/wp\/v2\/media\/375"}],"wp:attachment":[{"href":"https:\/\/www.amp.legal\/blog\/wp-json\/wp\/v2\/media?parent=308"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.amp.legal\/blog\/wp-json\/wp\/v2\/categories?post=308"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.amp.legal\/blog\/wp-json\/wp\/v2\/tags?post=308"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}