Equifax breach may be caused due to Apache Struts vulnerability

Date:

Share post:

The recent data breach suffered by Equifax seems to be due to vulnerability in the open-source Apache Struts Framework, as suggested by a Baird Equity Research report. Equifax has neither publicly confirmed nor denied that the flaw in Apache Struts is the root cause of the incident, though the company has admitted that a Web application vulnerability may be the reason behind the breach.

The Apache Software Foundation said that Struts may have been the reason for the breach that potentially compromised sensitive information for 143 million American consumers. In a statement, René Gielen, vice president of Apache Struts, said, “We are sorry to hear the news that Equifax suffered from a security breach and information disclosure incident that was potentially carried out by exploiting a vulnerability in the Apache Struts Web Framework. At this point in time, it is not clear which Struts vulnerability would have been utilized if any.

Equifax discovered the breach on July 29, 2017, but had waited until after the close of trading nearly six weeks later to disclose the breach to consumers and Equifax’s investors. As part of its investigation of this application vulnerability, Equifax  identified unauthorized access to limited personal information for certain UK and Canadian residents. The company found no evidence that personal information of consumers in any other country has been impacted.

Earlier this week, it was reported that shareholder Rights Law Firm Johnson Fistel, LLP (formerly Johnson & Weaver, LLP) is investigating potential violations of the federal securities laws by Equifax Inc. and certain of its officers.

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

The Cyber Security EXPO is the only dedicated recruitment event for Cyber Security Professionals

Located in the heart of London at the QEII Centre, the Cyber Security EXPO London offers a prime...

Atlanta Set to Host Hacker Halted and Global CISO Forum 2026, Uniting Practitioners and C-Suite Leaders

The Westin Peachtree Plaza will anchor a week of hands-on training, offensive security research, and closed-door executive dialogue...

From Awareness to Relevance: Rethinking How We Teach Cybersecurity

Cybersecurity lessons have a better chance to endure when people first understand how the same risks affect their...

CyberSec Delhi Conference 2026

Securing India’s Power, Defence, Manufacturing & Industrial Ecosystems The CyberSec Delhi Conference 2026 will bring together policymakers, government stakeholders,...