Equifax software bug messed up credit score calculations for weeks
(2022/08/03)
- Reference: 1659552247
- News link: https://www.theregister.co.uk/2022/08/03/equifax_code_issue/
- Source link:
US credit agency Equifax says errant computer code led the company to provide inaccurate credit information about US folks to financial institutions for a period of about three weeks earlier this year.
"Equifax identified a coding issue within a legacy, on-premise server environment in the US slated to be migrated to the new Equifax Cloud infrastructure," the biz said on Tuesday in [1]a statement .
The company said the glitch occurred between March 17 and April 6, 2022, when the issue was fixed, and "resulted in the potential miscalculation of certain attributes used in model calculations."
[2]
Equifax said, "credit reports were not changed as a result of this issue," though the Wall Street Journal [3]noted the credit scores provided to financial firms in conjunction with consumer applications for auto loans, mortgages, and credit cards were off by 20 points or more, enough to alter lender credit decisions.
[4]
[5]
In its statement, Equifax said its analysis of the consequences of the coding issue indicates "the vast majority" of credit scores were unaffected. For those who were affected, the company said, "initial analysis indicates that only a small number of them may have received a different credit decision."
According to the corporation, fewer than 300,000 consumers saw a credit score shift of 25 points or more. The Wall Street Journal says lenders have asked Equifax for more details and may consider repricing loans or giving denied loan applicants the opportunity to reapply.
[6]
The Register asked Equifax whether it would be more specific about the nature of the "code issue" that altered people's credit scores. We've not heard back. We also asked the US Consumer Financial Protection Bureau to comment and the agency declined.
[7]NASA's CAPSTONE silence down to a software flaw
[8]Google fixes 'Chromebork' one-character code typo that prevented Chrome OS logins
[9]Airline flight loads miscalculated because adult passengers using 'Miss' were treated as children
National Mortgage Professional first [10]reported the snafu in late May. The banking trade publication said the error affected mortgage clients receiving consumer credit scores via Equifax's legacy online model platform, known as OMS.
An unnamed source told the publication that in certain transactions, attribute values such as "number of inquiries within one month" or "age of oldest tradeline" were sometimes incorrect. These errors are said to have affected about 12 percent of credit score calculations.
In 2017, Equifax was compromised in a cyberattack that the company attributes [11]to the Chinese military . The intrusion was made possible by [12]an employee running an unpatched and thus insecure version of Apache Struts. Personal information for about 146.6 million people in the US, Canada, and the UK is said to have been taken as a result of the incident.
The massive hack led Equifax to invest $1.5 billion "to build a top-tier, cloud-native technology and security infrastructure," as the company puts it.
[13]
Yet the remedial infrastructure and security investment evidently failed to prevent the "coding issue."
Equifax suggests that by accelerating its migration of the affected on-premises environment to the cloud, the availability of additional controls and monitoring will help catch and prevent similar problems in the future.
We can only hope. ®
Get our [14]Tech Resources
[1] https://www.equifax.com/newsroom/all-news/-/story/equifax-statement-on-recent-coding-issue/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YurwFFzD-6dkP@N84DdN9QAAAFU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.wsj.com/articles/equifax-sent-lenders-inaccurate-credit-scores-on-millions-of-consumers-11659467483
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YurwFFzD-6dkP@N84DdN9QAAAFU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YurwFFzD-6dkP@N84DdN9QAAAFU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YurwFFzD-6dkP@N84DdN9QAAAFU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2022/07/08/capstone_software_bug/
[8] https://www.theregister.com/2021/07/23/chromebork_bug_google/
[9] https://www.theregister.com/2021/04/08/tui_software_mistake/
[10] https://nationalmortgageprofessional.com/news/equifax-telling-lenders-potential-errors-credit-scores
[11] https://www.equifax.com/newsroom/all-news/-/story/reengineering-a-123-year-old-company-how-equifax-emerged-as-a-high-tech-leader-in-security-and-innovation/
[12] https://www.theregister.com/2017/10/04/sole_security_worker_at_fault_for_equifax_fail_says_former_ceo/
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YurwFFzD-6dkP@N84DdN9QAAAFU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://whitepapers.theregister.com/
"Equifax identified a coding issue within a legacy, on-premise server environment in the US slated to be migrated to the new Equifax Cloud infrastructure," the biz said on Tuesday in [1]a statement .
The company said the glitch occurred between March 17 and April 6, 2022, when the issue was fixed, and "resulted in the potential miscalculation of certain attributes used in model calculations."
[2]
Equifax said, "credit reports were not changed as a result of this issue," though the Wall Street Journal [3]noted the credit scores provided to financial firms in conjunction with consumer applications for auto loans, mortgages, and credit cards were off by 20 points or more, enough to alter lender credit decisions.
[4]
[5]
In its statement, Equifax said its analysis of the consequences of the coding issue indicates "the vast majority" of credit scores were unaffected. For those who were affected, the company said, "initial analysis indicates that only a small number of them may have received a different credit decision."
According to the corporation, fewer than 300,000 consumers saw a credit score shift of 25 points or more. The Wall Street Journal says lenders have asked Equifax for more details and may consider repricing loans or giving denied loan applicants the opportunity to reapply.
[6]
The Register asked Equifax whether it would be more specific about the nature of the "code issue" that altered people's credit scores. We've not heard back. We also asked the US Consumer Financial Protection Bureau to comment and the agency declined.
[7]NASA's CAPSTONE silence down to a software flaw
[8]Google fixes 'Chromebork' one-character code typo that prevented Chrome OS logins
[9]Airline flight loads miscalculated because adult passengers using 'Miss' were treated as children
National Mortgage Professional first [10]reported the snafu in late May. The banking trade publication said the error affected mortgage clients receiving consumer credit scores via Equifax's legacy online model platform, known as OMS.
An unnamed source told the publication that in certain transactions, attribute values such as "number of inquiries within one month" or "age of oldest tradeline" were sometimes incorrect. These errors are said to have affected about 12 percent of credit score calculations.
In 2017, Equifax was compromised in a cyberattack that the company attributes [11]to the Chinese military . The intrusion was made possible by [12]an employee running an unpatched and thus insecure version of Apache Struts. Personal information for about 146.6 million people in the US, Canada, and the UK is said to have been taken as a result of the incident.
The massive hack led Equifax to invest $1.5 billion "to build a top-tier, cloud-native technology and security infrastructure," as the company puts it.
[13]
Yet the remedial infrastructure and security investment evidently failed to prevent the "coding issue."
Equifax suggests that by accelerating its migration of the affected on-premises environment to the cloud, the availability of additional controls and monitoring will help catch and prevent similar problems in the future.
We can only hope. ®
Get our [14]Tech Resources
[1] https://www.equifax.com/newsroom/all-news/-/story/equifax-statement-on-recent-coding-issue/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YurwFFzD-6dkP@N84DdN9QAAAFU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.wsj.com/articles/equifax-sent-lenders-inaccurate-credit-scores-on-millions-of-consumers-11659467483
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YurwFFzD-6dkP@N84DdN9QAAAFU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YurwFFzD-6dkP@N84DdN9QAAAFU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YurwFFzD-6dkP@N84DdN9QAAAFU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2022/07/08/capstone_software_bug/
[8] https://www.theregister.com/2021/07/23/chromebork_bug_google/
[9] https://www.theregister.com/2021/04/08/tui_software_mistake/
[10] https://nationalmortgageprofessional.com/news/equifax-telling-lenders-potential-errors-credit-scores
[11] https://www.equifax.com/newsroom/all-news/-/story/reengineering-a-123-year-old-company-how-equifax-emerged-as-a-high-tech-leader-in-security-and-innovation/
[12] https://www.theregister.com/2017/10/04/sole_security_worker_at_fault_for_equifax_fail_says_former_ceo/
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/applications&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YurwFFzD-6dkP@N84DdN9QAAAFU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://whitepapers.theregister.com/
I smell
JimmyPage
a class action lawsuit.
Whaaaa?
"The massive hack led Equifax to invest $1.5 billion "to build a top-tier, cloud-native technology and security infrastructure," as the company puts it."
Cloud-native and secure aren't two things I'd put together. There is a huge attack surface with "cloud" things and often a large number of players involved as companies outsource so many things these days. Frankly, I'd feel much more secure if Equifax said they bought a disused mine or three and located their hardware on the lowest levels guarded by lots of reinforced concrete and vault doors to prevent physical attacks and institute strict access control and deployed many of their own data connections so they could better monitor access there as well.
Botching important software and doing deployments without proper testing is universal these days as companies race to the be first with something rather than the best.