Home Security IRS puts Equifax contract on hold after malware find

IRS puts Equifax contract on hold after malware find

The US Internal Revenue Service has temporarily suspended a short-term contract worth US$7.25 million with credit information provider Equifax for identity proofing services.

This follows the discovery that Equifax, which announced that it had suffered a breach that put the details of 145.5 million Americans at risk, was serving malware from one of its sites.

The contract was announced in the first week of October.

Equifax disclosed the breach of the data of up to 143 million Americans on 7 September. Later it said an additional 2.5 million Americans could be affected.

The IRS said in a statement that during the suspension it would continue reviewing the systems and security at Equifax.

"There is still no indication of any compromise of the limited IRS data shared under the contract," the agency said.

The awarding of the contract was questioned by Senators Ben Sasse (Republican, Nebraska) and Elizabeth Warren (Democrat, Massachusetts) in a letter sent to the IRS commissioner.

Equifax denied that it was serving malware from any part of its website and blamed a third-party vendor.

"Despite early media reports, Equifax can confirm that its systems were not compromised and that the reported issue did not affect out consumer online dispute portal," the company said in a statement.

"The issue involves a third-party vendor that Equifax uses to collect website performance data. That vendor's code running on an Equifax website was serving malicious content.

"Since we learned of the issue, the vendor's code was removed from the Web page, and we have taken the Web page offline to conduct further analysis."


Did you know: 1 in 10 mobile services in Australia use an MVNO, as more consumers are turning away from the big 3 providers?

The Australian mobile landscape is changing, and you can take advantage of it.

Any business can grow its brand (and revenue) by adding mobile services to their product range.

From telcos to supermarkets, see who’s found success and learn how they did it in the free report ‘Rise of the MVNOs’.

This free report shows you how to become a successful MVNO:

· Track recent MVNO market trends
· See who’s found success with mobile
· Find out the secret to how they did it
· Learn how to launch your own MVNO service


Sam Varghese

website statistics

A professional journalist with decades of experience, Sam for nine years used DOS and then Windows, which led him to start experimenting with GNU/Linux in 1998. Since then he has written widely about the use of both free and open source software, and the people behind the code. His personal blog is titled Irregular Expression.