← Back to projects
CASE FILE 03 · INCIDENT ANALYSIS
Anatomy of a Cyber Attack: Equifax Data Breach
A structured analysis of the Equifax breach lifecycle, mapping attacker activity to MITRE ATT&CK and examining control weaknesses across patching, vulnerability management, segmentation and monitoring.
Objective
Analyze the Equifax breach as a cybersecurity case study, trace the attack lifecycle and translate the incident into practical lessons for defensive security.
Attack lifecycle & MITRE ATT&CK
Mapped the attack from initial access through data exfiltration and used the MITRE ATT&CK framework to identify attacker tactics, techniques and procedures.
Control gaps assessed
- Patch-management weaknesses.
- Vulnerability-management deficiencies.
- Network segmentation gaps.
- Security monitoring and visibility limitations.
Recommended security controls
- SIEM-based monitoring and improved alert visibility.
- Multi-factor authentication.
- Data Loss Prevention controls.
- Regular vulnerability scanning and remediation.
- Formalized incident-response procedures.
Key learning
The case highlights how unaddressed vulnerabilities and weak monitoring can compound into large-scale organizational risk, reinforcing the importance of patch discipline, visibility and coordinated response.