Skip to main content

Credit union hacks continue with Equifax and TransUnion malware attacks

equifax flash download
If Equifax thought the resignation of its CEO would be the beginning of the end of its catastrophic security debacle, it was sorely mistaken. This week has seen it attacked again, ultimately redirecting visitors to fake Flash Player updates and malware. It wasn’t the only one either, as TransUnion’s Central American website began doing the same this week.

Although there have been many large hacks over the past few years, the Equifax one was easily one of the worst. Affecting more than 145 million Americans and severely compromising the identity of hundreds of thousands, it left the majority of the country vulnerable to fraud. But it appears as if the Equifax security woes are far from over.

Recommended Videos

When security researcher, Randy Abrams attempted to visit the Equifax site to check some information on his credit report, he found himself redirected to a malicious URL which claimed his Flash players was out of date. That is a familiar scam message to anyone who has been on the internet for long enough, but it was a surprise to see the scam affect Equifax’s site so soon after it was breached earlier.

Please enable Javascript to view this content

As Ars Technica pointed out, such campaigns are often a flash in the pan, but not in this instance. The Equifax site continued to redirect the discoverer to a nefarious alternative site for several attempts.

What is even more worrisome about this, is that people affected by the Equifax hack — as Abrams was — will visit its site to learn more or to mitigate problems it might cause and will be faced with yet another security threat. Fortunately, at the time of writing, it appears to have been fixed, though the resource the previously infected link was supposed to send visitors to is “down for maintenance.”

It appears, too, that the Equifax hack has emboldened hackers to target other credit check agencies too. In a separate incident, the same sort of malicious, faux Flash Player update demands was found on the TransUnionCentroAmerica.com website, Ars Technica reported. Although more sporadic than the Equifax attack, links on its site sent people to malicious pages suggesting they install an update, only to instead download malware.

In some cases, the download would deliver an exploit kit that would try to infect further parts of the browser or system.

TransUnion is said to be aware of the issue and claims to have fixed it. It is also said to be looking into its other online properties to make sure the nefarious links cannot be found elsewhere on its online services.

For those still concerned about your Equifax data, we have a guide on how to secure your information. It’s also worth considering enacting a credit freeze.

Jon Martindale
Jon Martindale is a freelance evergreen writer and occasional section coordinator, covering how to guides, best-of lists, and…
Yes, it’s real: ChatGPT has its own 800 number
1-800-chatgpt

On the 10th of its "12 Days of OpenAI" media event, the company announced that it has set up an 800 number (1-800-ChatGPT, of course) where anyone in the U.S. with a phone line can dial in and speak with the AI via Advanced Voice Mode. Because why not.

“[The goal of] OpenAI is to make artificial general intelligence beneficial to all of humanity, and part of that is making it as accessible as possible to as many people as we can,” the company's chief product officer, Kevin Weil, said during the Wednesday live stream. “Today, we’re taking the next step and bringing ChatGPT to your telephone.”

Read more
Steam Replay 2024 is live — here’s how to see yours
The Steam Replay 2024 profile showcase.

It's that time of year again -- time for Steam Replay. Similar to Xbox Year in Review and PlayStation Wrap-Up, Steam Replay 2024 looks back over your gameplay stats for the entire year, showing you what you've played, how long you've played it, and the feats you've accomplished along the way.

As usual, Steam Replay runs through the end of the year, so if you want to view your Replay and unlock the exclusive Steam Replay 2024 badge, you'll need to sign in soon. Thankfully, you can save your Steam Replay to your profile as a featured showcase, as well as share it out with your friends to view throughout the next year.
How to see Steam Replay 2024

Read more
Ray-Ban Meta Smart Glasses get real-time visual AI and translation
Tracey Truly shows multi-reflective options with Ray-Ban Meta Smart Glasses.

Meta is rolling out two long-awaited features to its popular Ray-Ban Smart Glasses: real-time visual AI and translation. While it's just being rolled out for testing right now, the plan is that, eventually, anyone that owns Ray-Ban Meta Smart Glasses will get a live assistant that can see, hear, and translate Spanish, French, and Italian.

It's part of the v11 update that cover the upgrades Meta described at its Connect 2024 event, which also include Shazam integration for music recognition. This all happens via the camera, speakers, and microphones built into the Ray-Ban Meta glasses, so you don’t need to hold up your phone.

Read more