当前位置:首页 >百科 >【】

【】

2026-05-05 21:53:47 [知識] 来源:有聲有色網

In failing to correctly patch a known vulnerability and exposing the personal data of potentially 143 million Americans to hackers, Equifax made a security blunder of epic proportions — however, it appears the company is just getting started.

Leaving its digital doors wide open to criminals apparently wasn't enough for the credit reporting agency, as it's now sending hack victims directly into the open arms of unknown internet pranksters.

Yes, Equifax is directing those concerned about the data breach and its repercussions to a fake website set up to troll the company itself. That's right, the official Equifax Twitter account is pointing people to what looks to be a fakesite (aka a phishing site).

SEE ALSO:Equifax screwed up yet again, and it's scrambling to fix this latest mess

Following a data breach of this size, it's not unusual to see websites pop up that mimic official help pages. Typically, the goal of these phishing sites is to trick worried consumers into handing over their personal information. In this case, Equifax created a very real site — https://www.equifaxsecurity2017.com — where people can enter their last name along with the last six digits of their social security number to see if they were affected by the hack.

Mashable Games

Unsurprisingly, someone cloned that site and hosted that copy at a very similar URL: https://securityequifax2017.com. The two sites, one real and one fake, look the same to the casual observer. In fact, they are so easily confused that Equifax itself apparently can't tell the difference.

Mashable ImageCome on, Tim.Credit: mashable

If you look closely at the above pictured Twitter exchange, you'll see that someone operating the Equifax account named Tim linked to the fake website. The timestamp on the tweet is from September 19, and the tweet was still up as of the morning of September 20 (it was deleted during the course of writing this story).

Also, this is not the only tweet that listed the incorrect website. It happened at least eight times.

Thankfully, the maker of the spoofed site seems more interested in calling out Equifax for their incompetence than stealing the personal information of unsuspecting victims. Probably.

Mashable Light SpeedWant more out-of-this world tech, space and science stories?Sign up for Mashable's weekly Light Speed newsletter.By signing up you agree to our Terms of Use and Privacy Policy.Thanks for signing up!

"Cybersecurity Incident & Important Consumer Information Which is Totally Fake, Why Did Equifax Use A Domain That's So Easily Impersonated By Phishing Sites," reads the header of the fake site.

"Equifax should have hosted this on equifax.com with a reputable [EV] SSL Certificate. Instead they chose an easily impersonated domain and used a jelly-bean SSL cert that any script kiddie can impersonate in 20min," the fake site adds.

Clicking through the links prompts a person to enter their last name and last six of their SSN, much like on the real Equifax site, but upon hitting "continue" the cloned webpage gives you a warning. "you just got bamboozled," reads a popup window. "this isnt a secure site [sic]! Tweet to @equifax to get them to change it to equifax.com before thousands of people loose [sic] their info to phishing sites!"

Mashable ImageThe fake phishing site.Credit: mashable

It's not clear if the site captures the data entered by a tricked consumer, or if it discards it. There is no real contact information on the page, and many of the links take you to a YouTube video for Rick Astley's "Never Gonna Give You Up" — a classic internet prank known as "rickrolling." A WHOIS lookup of the domain shows it was created on September 8, but does not list the owner.

Security researcher Nick Sweeting, however, has taken credit for the site, and claims he is not stealing any of the entered data.

"[Equifax's] response to this incident leaves millions vulnerable to phishing attacks on copycat sites," reads the fake page. "This is why you don't put your security incident website on a domain that looks like a scam (with an Amazon SSL cert), no-one can tell the difference between the real thing an a phishing site."

That the aforementioned "no-one" includes whoever's running Equifax's Twitter account doesn't bode well for the company — or anyone unlucky enough to have their personal information collated in its massive and poorly secured database.

What does Equifax have to say about all this? Unfortunately, not much.

“All posts using the wrong link have been taken down," a spokesperson told Mashable via email. "To confirm, the correct website is https://www.equifaxsecurity2017.com. We apologize for the confusion.”

No word yet on whether or not Tim will be forced to apologize to all of us directly.


Featured Video For You
This camera could keep you safe at your next protest

TopicsCybersecurity

(责任编辑:焦點)

    推荐文章
    • Satisfy your Olympics withdrawals with Nike's latest app

      Satisfy your Olympics withdrawals with Nike's latest appFollowing in the footsteps of last year's successful launch of Nike's Tech Book is back in its secon ...[详细]
    • 黃花菜木耳炒雞蛋的做法

      黃花菜木耳炒雞蛋的做法我們要健康地吃飯,就需要自己做飯菜來吃,隻有這樣才健康。為此 ,小編在這裏就先來說說關於黃花菜木耳炒雞蛋這道菜的做法 。1.黑木耳 、幹黃花菜洗淨泡發 ,分別去除老硬的根部 。2.入開水中焯熟備用。3.雞蛋打入 ...[详细]
    • 牛奶香蕉雞蛋羹的做法

      牛奶香蕉雞蛋羹的做法很多人都是家裏的獨生子女,他們的長大 ,都是父母的庇佑。而成人之後 ,脫離了父母的懷抱,他們很多人都不會吃飯了 ,因為沒人做了。麵對這樣的現實 ,你肯定不願意被餓死吧,所以你隻有自己動手。現在 ,小編就先來教大 ...[详细]
    • 白菜梗子炒瘦肉的做法

      白菜梗子炒瘦肉的做法作為一名資深吃貨,每當看到別人自己三下五除二的就整出一道好菜 ,你肯定備受打擊 。小編現在給大家介紹一道白菜梗子炒瘦肉的做法,你認真看完以後決定會有很大的收獲1.備豬瘦肉 ,白菜梗子,尖椒。2.將白菜梗子切 ...[详细]
    • U.S. pole vaulter skids to a halt for national anthem

      U.S. pole vaulter skids to a halt for national anthemAn American pole vaulter took his patriotism to the next level at the Olympics.。Sam Kendricks, a sec ...[详细]
    • 蔥香湯藕豬肉餅的做法

      蔥香湯藕豬肉餅的做法當你上了一天班回來,肯定覺得渾身疲憊 。當然 ,這時你也會覺得肚子空空的 ,如何填飽肚子呢  ?最好的莫過於自己下廚房了 。當你嚐到自己汗水中的美食,你肯定覺得無比香甜。下麵 ,就給大家嚐試做一下蔥香湯藕豬肉餅 。1 ...[详细]
    • 簡單係牛油曲奇的做法

      簡單係牛油曲奇的做法我們經常說的一句話就是病從口入 ,確實也是。很多疾病就是這樣的,我們平時飲食的不注意 ,所以我們不能老在外麵吃飯,可以自己做飯哦  ,下麵小編就介紹簡單係牛油曲奇1.老實招了,這張圖片一直到擠花紋的那張中間的 ...[详细]
    • Best monitor deal: Get a Dell monitor for $20 off plus a free $75 eGift Card

      Best monitor deal: Get a Dell monitor for $20 off plus a free $75 eGift CardSAVE $95: As of June 12, get a 27-inch Dell monitor (S2725H) at Dell for just $129.99, $20 off from ...[详细]
    • Singapore rolls out video

      Singapore rolls out videoSINGAPORE -- Getting stuff done at the bank often involves having to waste part of your day standing ...[详细]
    • 蔓越莓海綿蛋糕的做法

      蔓越莓海綿蛋糕的做法其實做菜沒有大家想象的那麽難 ,隻要你想學習,就可以慢慢練習的。小編下麵給大家介紹蔓越莓海綿蛋糕的做法,仔細看一下 ,相信你一定可以學會的1.準備好材料。2.準備一個大一點盆,裝入40度的熱水,打蛋盆一次 ...[详细]
    热点阅读