# GAO Report on Equifax

DevFeed: [GAO Report on Equifax](<https://devfeed.tech/articles/gao-report-on-equifax-36804.md>)

Original publisher: [Read original article](<https://shostack.org/blog/gao-report-on-equifax/>)

Author: Adam

Published: 2018-10-12T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Database](<https://devfeed.tech/topics/database.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [breach](<https://devfeed.tech/tags/breach.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [databases](<https://devfeed.tech/tags/databases.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [pii](<https://devfeed.tech/tags/pii.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

This commentary examines the GAO report on the 2017 Equifax breach and raises questions about how attackers gained system-level access, reached additional databases containing sensitive data, used unencrypted credentials, and evaded detection by blending malicious activity with normal network activity.

## Source excerpt

I still have questions...