Equifax SQL Injection
Equifax SQL Injection
Case Study
Equifax, affected millions of customers.
Description of the attack category:
SQL Injection is a type of cyber attack that exploits
vulnerabilities in web applications that use SQL
(Structured Query Language). Attackers insert
malicious code into web application input fields that
Attack execute SQL commands on the backend database,
potentially giving the attacker access to sensitive data.
Category
SQL Injection
Vulnerabilities
Vulnerability #3 Vulnerability #4
in settlements, fines, and other costs related to the Proper network segmentation and access controls
breach, including a $700 million settlement with the Implementation of encryption and other security
US Federal Trade Commission (FTC) and a $425 measures to protect sensitive data
million settlement with affected customers. Implementation of intrusion detection and response
manner.