Equifax has taken down a webpage after it directed users to install a fake Adobe Flash update containing adware; company blames third-party analytics vendor
Equifax said Thursday that its systems were not compromised, after they looked into a report by an independent researcher …
Context & Ripple Effects
This lands mid-collapse of Equifax's post-breach web presence. Within weeks of the 2017 breach disclosure, the company's breach-lookup tool was returning confusing or inaccurate results, its credit-monitoring site was found vulnerable to cross-site scripting, and its own customer-service account tweeted customers to a critic's phishing site for over a week. A webpage pushing a fake Flash update is the fourth self-inflicted wound in roughly a month.
The mechanism is not new either: when PageFair was hacked in 2015, malware reached visitors of over 500 sites through a single compromised service those sites had chosen to embed. Equifax's claim that a third-party analytics vendor caused this puts it in the same category — the brand takes the reputational hit for code it did not write but did install.
First-order effects
- Visitors to the affected Equifax page were prompted to install adware disguised as an Adobe Flash update; Equifax has pulled the page and says an independent researcher's report showed its core systems were not compromised.
Second-order effects
- The blame-the-vendor defense shifts scrutiny onto the analytics vendor and onto every third-party script Equifax embeds — during a breach-response period when each new incident compounds the credibility damage already done by the XSS finding and the phishing tweets.
Third-order effects
- If the PageFair-to-Equifax pattern holds, high-trust sites will face pressure to treat embedded third-party code as a supply-chain risk — with contractual security obligations and tighter vetting — because the hosting brand absorbs the fallout regardless of who wrote the code.
The trend: Third-party scripts embedded on trusted websites are becoming a recurring malware delivery channel, transferring security liability from niche vendors to the major brands that host them.