Skip to main content

Credit union hacks continue with Equifax and TransUnion malware attacks

equifax flash download
If Equifax thought the resignation of its CEO would be the beginning of the end of its catastrophic security debacle, it was sorely mistaken. This week has seen it attacked again, ultimately redirecting visitors to fake Flash Player updates and malware. It wasn’t the only one either, as TransUnion’s Central American website began doing the same this week.

Although there have been many large hacks over the past few years, the Equifax one was easily one of the worst. Affecting more than 145 million Americans and severely compromising the identity of hundreds of thousands, it left the majority of the country vulnerable to fraud. But it appears as if the Equifax security woes are far from over.

When security researcher, Randy Abrams attempted to visit the Equifax site to check some information on his credit report, he found himself redirected to a malicious URL which claimed his Flash players was out of date. That is a familiar scam message to anyone who has been on the internet for long enough, but it was a surprise to see the scam affect Equifax’s site so soon after it was breached earlier.

As Ars Technica pointed out, such campaigns are often a flash in the pan, but not in this instance. The Equifax site continued to redirect the discoverer to a nefarious alternative site for several attempts.

What is even more worrisome about this, is that people affected by the Equifax hack — as Abrams was — will visit its site to learn more or to mitigate problems it might cause and will be faced with yet another security threat. Fortunately, at the time of writing, it appears to have been fixed, though the resource the previously infected link was supposed to send visitors to is “down for maintenance.”

It appears, too, that the Equifax hack has emboldened hackers to target other credit check agencies too. In a separate incident, the same sort of malicious, faux Flash Player update demands was found on the TransUnionCentroAmerica.com website, Ars Technica reported. Although more sporadic than the Equifax attack, links on its site sent people to malicious pages suggesting they install an update, only to instead download malware.

In some cases, the download would deliver an exploit kit that would try to infect further parts of the browser or system.

TransUnion is said to be aware of the issue and claims to have fixed it. It is also said to be looking into its other online properties to make sure the nefarious links cannot be found elsewhere on its online services.

For those still concerned about your Equifax data, we have a guide on how to secure your information. It’s also worth considering enacting a credit freeze.

Editors' Recommendations

Jon Martindale
Jon Martindale is the Evergreen Coordinator for Computing, overseeing a team of writers addressing all the latest how to…
Why Llama 3 is changing everything in the world of AI
Meta AI on mobile and desktop web interface.

In the world of AI, you've no doubt heard about what OpenAI and Google have been up to. And now, Meta's Llama LLM (large language model) is becoming an increasingly important player in the game, especially with its open-source nature. Meta recently made a big splash with the launch of its Llama 3 AI model, and it's shaken up the field dramatically.

The reasons why are multiple and varied. It's free to use, it has a wide user base, and yes, it's open source, to name but a few. Here's why Llama 3 is taking the AI industry by storm and may shape its future for some time to come.
Llama 3 is really good
We can debate until the cows come home about how useful AIs like ChatGPT and Llama 3 are in the real world -- they're not bad at teaching you board game rules -- but the few benchmarks we have for how capable these AI are give Llama 3 a distinct advantage.

Read more
How to delete messages on your Mac
A MacBook and iPhone in shadow on a surface.

Apple likes to make things easy for its iPhone, iPad, and macOS devotees. When signed in with the same Apple ID on more than one of these devices, you’ll be able to sync your messages from one Apple product to the next. This means when you get a text on your iPhone, you’ll be able to pull it up through the Messages app on your Mac desktop.

Read more
The best laptop brands for 2024
best laptop brands hp spectre x360 13  2021 1

If you like to write, browse, game, or work in different parts of your home or office, one of the best laptops is a necessity in 2024. There are many to choose from, but you can first narrow your options by looking at laptops from the most established and respected brands.

Here's a list of the best laptop brands in 2024 to get you started.
Dell

Read more