3 ms·
That's ridiculous, they were hacked through Struts CVE-2018-11776 that was discovered a month before the hack, if appointed security officer was monitoring CVE
by altmind 7y ago
That's ridiculous, they were hacked through Struts CVE-2018-11776 that was discovered a month before the hack, if appointed security officer was monitoring CVE lists for their software, this would be patched.
Moreover, their DLP system was offline for the period of hack due to certificate expiration.
IANAL, but there was a clear case of negligence.
-- ed:
There were winning cases against equifax. the payout was awarded for the damages - 3 years of credit counceling and monitoring, something in $6k range.