Skip to main content

Equifax Twitter Account Links Worried Customers to a Spoof Site

After 143 Million people were affected by a security breach in Equifax, the company created another site directing customers to check whether their data including name, social security number, and other private information has been compromised or not. Sadly, it led to another “oops” moment for the company when their twitter account linked the bereaved customers to a spoof site.

Equifax has created equifaxsecurity2017.com to help worried customers identify if they have been hacked or are in the safe zone. However, the site was a separate domain and quite easy to replicate.

“I created the clone in less than 20 minutes”- Nick Sweeting, creator of Spoof Site

Nick Sweeting, a full stack developer decided to show the company and the consumers about the vulnerabilities within the site and created the clone in less than 20 minutes. He told an associated press how he used a command in Linux called wget and downloaded all the images, CSS and HTML code of the original site.

He then fed it to a $5 server and created the clone in under 20 minutes with the aim of bringing it to the notice of all Equifax users. Also, he ensured the people that all their data was not stored as the form was actually disabled.

“It was super easy to just suck their whole site down with wget and throw it on a $5 server. It currently has the same type of SSL certificate as the real version, so from a trust perspective, there’s no way for users to authenticate the real one vs. my server.”- Nick Sweeting

After the site got blacklisted by Google Safe browsing, he has since taken it down and assured user how it wasn’t malicious but just a small effort on his part to show the vulnerabilities and poor design of the Equifax site.

It should have been built as a subdomain of an Official Site

Cyber Analysts have been criticizing the Equifax for using a separate domain for their “security improvement” site. They shared how it should have been built as part of the official site, perhaps as a subdomain to recognize other malicious and fake sites easily.

The one created by Nick Sweeting played on the URL by preceding equifax after security. His fake site was called securityequifax2017.com while the original one is equifaxsecurity2017.com. The URL is quite easy to be confused with.

So, it doesn’t come as a surprise when the site received more than 2000 hits which turned to around 200,000 when Equifax Customer Support employee redirected the concerned customers to the lookalike site by mistake.

The spokesperson for Equifax apologized for the confusion in a written email sent to Associated Press. They also mentioned that all the wrong tweets have been since deleted.

“All posts using the wrong link have been taken down. To confirm, the correct website is http://ift.tt/2xdYnYt. We apologize for the confusion.”

From all the wrong tweets, it can be gathered that they came from a customer support employee or maybe an intern called “Tim”. Hoping he doesn’t get fired, Nick stated that it was not his fault but merely a major issue with Equifax who are still not amping up the security after the major breach that compromised data of millions of users posing them at risk of hackers and cybercrime.

“I just hope the employee who posted the tweet doesn’t get fired, they probably just Googled for the URL and ended up finding the fake one instead. The real blame lies with the people who originally decided to set the site up badly.” – Said by Nick Sweeting.

Apart from a written apology email, Equifax was not available for another response on the matter.

The post Equifax Twitter Account Links Worried Customers to a Spoof Site appeared first on CTN News.



from CTN News http://ift.tt/2hmcZuq
via IFTTT http://ift.tt/2s3YPq1

Comments

Popular posts from this blog

Facebook Personal Information Leaked Through The “Like” Button

Facebook Personal Information Leaked Through The “Like” Button : The Government of Japan today urged Facebook to improve the protection of It’s personal data, following the succession of incidents in which information has been leaked from millions of users of the social network throughout the world. -Japan urges Facebook to improve the protection of personal data . The  Committee of Protection of Information   in japan adopted a resolution in which it urges  Facebook  to  take measures to avoid similar cases, as the first warning directed to the American giant of Internet. Google Offering Products Based On User Data To Increase Revenue The document states that personal information of users of the social network included in their profiles or their browsing history  were automatically transferred to external pages of Facebook that had a link to the “like” button   , even if Internet users did not click on it. Therefore, he asks Facebook to “give clearer explanations about  h

Death of young puppy aboard United flight triggers United States department inquiry

United Airlines dealt with new reactions on Wednesday regarding a young puppy dog which passed away in-flight soon after an attendant ordered it stored in an overhead box. The United States Department of Transportation stated it is taking a look at the events which resulted in the bulldog’s demise. UNITED STATE Legislator John Kennedy, whom previously on Wednesday sent out a letter to the United Airlines Commander in chief Scott Kirby, asking for relevant information regarding the significant amount of pets which have passed away while in the transporter’s care, published on Twitter that he intended to submit a bill on Thursday which will restrict airline companies from placing pets inside overhead receptacles. ” Violators will face significant fines. Pets are family,” he noted. Kennedy, within the correspondence, stated United’s “pattern of animal deaths and injuries is simply inexcusable.” The man mentioned that the numbers occurred while on air-planes  is  24 pets, which pas