Justice Dept. has charged four Chinese military hackers over the Equifax data breach
U.S. prosecutors have charged four Chinese military hackers over the 2017 cyberattack at Equifax, which resulted in a data breach involving more than 147 million credit reports.
Attorney general William Barr said the four hackers were members of the Chinese People’s Liberation Army.
The nine-charge indictment was announced Monday against Wu Zhiyong, Wang Qian, Xu Ke, and Liu Lei, which the Justice Department said made up part of the APT10 group, a notorious state-backed hacking group that was previously blamed for hacking into dozens of major U.S. companies and government systems, including HPE, IBM, and NASA’s Jet Propulsion Laboratory.
Barr said it was the latest in a long line of state-backed cyberattacks that targeted health insurance giant Anthem, the Marriott Starwood hotel breach, and the U.S. Office of Personnel Management, which saw the theft of millions of government workers’ biometric files.
“This is the largest theft of sensitive personal identifiable information by state-sponsored hackers ever recorded,” said FBI deputy director David Bowdich, at a presser in Washington DC.
Four Chinese military hackers are accused of hacking into Equifax in 2017. (Image: Justice Dept./handout
Equifax revealed the data breach in September 2017, months after it discovered hackers had broken into its systems.
An investigation showed the company failed to patch a web server it knew was vulnerable for weeks, which let hackers crash the servers and steal massive amounts of personal data. Names, addresses, Social Security numbers and more — and millions more driver license and credit card numbers were stolen in the breach. The data breach also affected British and Canadian nationals.
Equifax chief executive Richard Smith retired shortly after the breach, but didn’t escape criticism. Sen. Chuck Schumer called the breach and the credit giant’s handling of the aftermath “one of the most egregious examples of corporate malfeasance since Enron.”
Equifax later settled with the Federal Trade Commission to pay at least $575 million in fines.
“Today, we hold [the Chinese military] hackers accountable for their criminal actions, and we remind the Chinese government that we have the capability to remove the Internet’s cloak of anonymity and find the hackers that nation repeatedly deploys against us,” said Barr.
Neither Equifax nor the Chinese Consulate in New York immediately responded to requests for comment.