Fake Website Fools Equifax Staff

Equifax logoImage copyright EPA

Credit rating firm Equifax has apologised after it mistakenly directed some customers to an imposter website via its Twitter page.

The firm recently disclosed a data breach affecting more than 143 million people, and set up a new website to share information with customers.

But it mistakenly tweeted the wrong web address several times, leading some customers to a fake website.

One security researcher told the BBC it was a "massive faux-pas".

Image caption The fake Equifax website looked just like the real thing, but was critical of the company

Following its data breach, Equifax set up a new website - equifaxsecurity2017.com - to let people find out more information.

The website also let people register for a credit monitoring service, by entering personal details into a form.

Many security researchers said Equifax should have hosted this information on its main website - equifax.com - rather than setting up a new one.

They pointed out that the new web address looked like one a scammer might set up to try to fool victims.

Security researcher Nick Sweeting tweeted: "Yeah... no thanks... it would take me literally 20 mins to build a clone of this site."

He then did exactly that, creating an almost identical version of the website at securityequifax2017.com.

His fake version of the website also let people fill in their personal information - but then told them they had been "bamboozled".

Staff operating the Equifax twitter feed shared the fake website with customers several times.

Image copyright Twitter.com/Equifax
Image caption The incorrect tweets have since been deleted

In a statement, Equifax said: "All posts using the wrong link have been taken down. We apologise for the confusion.

"Consumers should be aware of fake websites purporting to be operated by Equifax. Our dedicated website for consumers to learn more about the incident and sign up for free credit monitoring is equifaxsecurity2017.com and our US company homepage is equifax.com."

Faux-pas

"Clearly, the social media team has not been thoroughly briefed," said Ken Munro from the security firm Pen Test Partners.

"That's a massive faux-pas, they should not be pointing people to a website that is not the real one.

"They are lucky the person behind it was a well-intentioned security researcher, it could easily have been somebody harvesting credentials."

Criminals often use a widely-publicised data breach to try and fool victims into handing over more of their personal data.

"People have to be careful after a data breach. Hackers often email victims trying to spoof the affected organisations," said Mr Munro.

"You might get phone calls from people pretending to be from the support team. We see this all the time - be on your guard."

RECENT NEWS

The Global Semiconductor Landscape: Navigating Through Market Shifts Post Samsung's Earnings Triumph

In the first quarter of 2024, Samsung Electronics announced a staggering 931% surge in operating profits, reaching 6.6 t... Read more

The Balancing Act: Google's Paywalled AI And The Quest For Digital Equity

In an era where artificial intelligence (AI) is no longer the stuff of science fiction but a daily utility, Google's lat... Read more

The Meteoric Rise Of Anthropic: Valuation And The Future Of AI

In an era where artificial intelligence (AI) is not just a buzzword but a cornerstone of technological advancement, Amaz... Read more

The Future Of Sports Strategy: Navigating The AI Revolution

In the fast-evolving world of competitive sports, the introduction of Artificial Intelligence (AI) has been nothing shor... Read more

The Future Of Sports Strategy: Navigating The AI Revolution

In the fast-evolving world of competitive sports, the introduction of Artificial Intelligence (AI) has been nothing shor... Read more

Beyond The Hype: The Harmonious Fusion Of AI And Music Genres

In the evolving symphony of the music industry, artificial intelligence (AI) is no longer just a futuristic concept but ... Read more