{
  "id": "case-wu-equifax-pla",
  "slug": "us-v-wu-equifax-pla",
  "title": "U.S. v. Wu et al. (Equifax PLA Unit 54th Research Institute)",
  "summary": "Four military officers with the Chinese People's Liberation Army (PLA) 54th Research Institute charged with hacking into Equifax networks, stealing trade secrets, and exfiltrating personally identifiable information (PII) of roughly 147 million American citizens.",
  "case_number": "1:20-cr-00071",
  "court": "U.S. District Court for the Northern District of Georgia",
  "district": "N.D. Ga.",
  "country": "United States",
  "opened_at": "2020-01-28",
  "status": "fugitive",
  "victim_sector": "Financial Services, Consumer Credit",
  "victim_country": "United States",
  "loss_amount_usd": 1400000000,
  "loss_amount_note": "Equifax incurred over $1.4 billion in remediation, technological overhauls, and federal class action settlement expenditures.",
  "first_seen_at": "2017-05-13T00:00:00Z",
  "last_updated_at": "2026-09-15T12:00:00Z",
  "actor_slug": "pla-unit-54th",
  "defendant_slugs": [
    "wu-zhiyong",
    "wang-qian",
    "xu-ke",
    "liu-lei"
  ],
  "cves": [
    "CVE-2017-5638"
  ],
  "techniques": [
    {
      "technique_id": "T1190",
      "evidence_excerpt": "The conspirators exploited a known vulnerability in the Apache Struts Web Framework (CVE-2017-5638) on Equifax's online dispute portal to obtain initial remote shell execution.",
      "evidence_locator": "Indictment \u00b6 14, Page 6",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Wu et al.",
      "source_url": "https://www.justice.gov/opa/pr/chinese-military-personnel-charged-computer-fraud-economic-espionage-and-wire-fraud-hacked",
      "technique_name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1070",
      "evidence_excerpt": "Defendants routinely deleted temporary files and log entries, routed communications through encrypted tunnels, and ran roughly 9,000 queries to mask their database reconnaissance.",
      "evidence_locator": "Indictment \u00b6 22, Page 11",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Wu et al.",
      "source_url": "https://www.justice.gov/opa/pr/chinese-military-personnel-charged-computer-fraud-economic-espionage-and-wire-fraud-hacked",
      "technique_name": "Indicator Removal",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1567",
      "evidence_excerpt": "Operatives packaged stolen records containing names, Social Security numbers, and birth dates into compressed archives and exfiltrated them to overseas staging servers.",
      "evidence_locator": "Indictment \u00b6 26, Page 13",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment",
      "source_url": "https://www.justice.gov/opa/pr/chinese-military-personnel-charged-computer-fraud-economic-espionage-and-wire-fraud-hacked",
      "technique_name": "Exfiltration Over Web Service",
      "tactic": "Exfiltration"
    }
  ],
  "events": [
    {
      "event_type": "indictment",
      "event_date": "2020-01-28",
      "description": "Federal grand jury returns nine-count indictment against four Chinese PLA military intelligence hackers."
    },
    {
      "event_type": "advisory",
      "event_date": "2020-02-10",
      "description": "Attorney General William Barr publicly announces the unsealing of charges against members of the 54th Research Institute."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Remote code execution via an unpatched Apache Struts vulnerability (CVE-2017-5638) on Equifax's public online dispute portal, which remained vulnerable for 66 days despite the release of a security patch.",
    "blast_radius": "Compromised the sensitive personally identifiable information (PII) of approximately 147 million Americans, including names, Social Security numbers, dates of birth, and driver's license numbers. Equifax spent over $1.4 billion on remediation, infrastructure overhauls, and federal class-action settlements.",
    "kill_chain": [
      {
        "phase": "Initial Exploitation",
        "title": "Apache Struts Web Server RCE",
        "description": "Chinese PLA military intelligence hackers exploited CVE-2017-5638 by sending malicious HTTP requests with crafted Content-Type headers, executing commands with web server privileges.",
        "technical_artifacts": [
          "CVE-2017-5638",
          "Apache Struts OGNL expression payload",
          "China Chopper webshell"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Internal Reconnaissance & Queries",
        "title": "Database Schema and Credentials Enumeration",
        "description": "Operatives ran approximately 9,000 internal database queries to locate consumer credit data, extracting unencrypted credentials stored in plaintext configuration files.",
        "technical_artifacts": [
          "Plaintext database credentials",
          "Automated SQL reconnaissance scripts"
        ],
        "mitre_technique_id": "T1083"
      },
      {
        "phase": "Defense Evasion",
        "title": "Log Purging and Encrypted Tunneling",
        "description": "Defendants established encrypted communications through proxy servers in Germany and Switzerland and systematically purged server access logs daily to conceal their presence.",
        "technical_artifacts": [
          "SSH encrypted tunnels",
          "log wipe commands"
        ],
        "mitre_technique_id": "T1070"
      },
      {
        "phase": "Exfiltration",
        "title": "Segmented Archive Cloud Exfiltration",
        "description": "Stolen records were split into compressed archives and exfiltrated to overseas staging servers over 76 separate intrusion days.",
        "technical_artifacts": [
          "tar.gz archives",
          "Segmented file downloads"
        ],
        "mitre_technique_id": "T1567"
      }
    ],
    "defensive_takeaways": [
      "Maintain an authoritative software asset inventory to identify and patch vulnerable software components within 48 hours of public CVE disclosure.",
      "Deploy Web Application Firewalls (WAF) with inspection rules for malicious HTTP headers and OGNL injection attacks.",
      "Encrypt sensitive database fields at rest and prohibit plaintext credentials in application config files.",
      "Inspect outbound SSL/TLS traffic with network decryption to detect unauthorized bulk data exfiltration."
    ]
  }
}