Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Equifax Partner Breach
News & Analysis

Equifax Partner Breach

ISBuzz TeamBy ISBuzz TeamFebruary 14, 20194 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Most Commonly Used Passwords Of 2018
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Cybercriminals found a way to penetrate Image-I-Nation Technologies is a North Carolina-based provider of software and hosting services, a company that services the three largest credit reporting services including Equifax. The hackers had access to sensitive information including social security numbers.

https://twitter.com/CtacPaladion/status/1095912543992700928

Image-I-Nation #DataBreach. https://t.co/DOmI2Ea9Bm

— TechNadu (@TechNadu) February 14, 2019

Experts Comments below:

Tim Mackey, Technical Evangelist at Synopsys:

“This breach disclosure highlights just how little control individuals have over the security and location of their personal data – let alone the purpose the data might be used for. Regardless of media coverage, it is highly unlikely that most people will pay attention to a data breach at Image-I-Nation Technologies considering they likely never directly did business with the company. In essence this is a repeat of the shock consumers experienced with the Equifax breach in 2017 and which spurred in part the enactment of the California Consumer Privacy Act (CCPA). Given the CCPA comes into effect in less than a year, it would be illustrative to look at this breach through that lens.

“Organisations doing business in the state of California which process information on more than 50,000 devices, individuals or households and which derives more than 50% of their revenue processing personal data would be subject to the CCPA. Consumers would be required to receive notification of the nature of collected data and the purpose of collecting the data when providing any data. Upon request, the organisation would be required to disclose in a human consumable format the collected data, the sources for the data, and the business purpose for both processing and sharing that data. In the event of unauthorised access to consumer data, including as a result of a data breach, the CCPA provides a consumers a right to bring suit against the organisation, including class-wide suits, and recover damages in an amount of not less than $100 per consumer per incident. While the number of California consumers impacted by the Image-I-Nation Technologies breach wasn’t disclosed, under CCPA it’s likely the potential civil suit would be substantial.

“Given the number of data protection laws appearing on the global stage, it’s clear that any business collecting or processing personal data needs to look closely at what data elements they collect, the purpose behind collection, the data retention policy and the consent obtained at the time of collection. Data warehouses with personal data are prime targets for malicious attacks. When the connection between consumer consent and the organisation storing the data is unclear, consumers are placed in a position where they can’t effectively manage and monitor their personal data. Only with greater transparency of data collection and processing practices can consumers effectively manage their digital privacy.”

Chris Olson, CEO at The Media Trust:

Chris Olson“If there is anything we’ve learned from the past few years’ breaches, third parties are an organization’s weakest links in the digital supply chain, and bad actors know it. It is therefore no surprise that the GDPR and, to some extent, California’s landmark consumer privacy law recognize the threats that third parties, unknowingly and otherwise, introduce. Since organizations are held at least partly responsible for their vendors’ actions, they should carefully vet the latter’s security and privacy measures and conduct periodic audits to close any security and privacy loopholes. As regulators ramp up their operations, they will no doubt make examples of high-profile violators of data privacy laws and impose penalties commensurate to their those violations.”

Matan Or-El, Co-founder and CEO at Panorays:

“The hack into Image-I-Nation Technologies, which is connected to the big three credit reporting companies, is a perfect example of how cybercriminals are infiltrating the supply chain to steal data from large organizations. Hackers were able to target a third party in order to gain access to social security numbers, names and addresses of consumers from three credit reporting companies. This breach illustrates why it’s crucial for organizations to perform comprehensive risk assessments of all their supply chain parstners, along with continuous monitoring to spot vulnerabilities.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}