Equifax is blaming an unspecified "website application vulnerability" in hackers' ability to get personal information on 143 million Americans. Security experts say it's hard to say for sure without more information, but such vulnerabilities typically don't require a lot of sophistication to exploit.
Rich Mogull, who runs the security research firm Securosis, says the web app breach suggests "things are broken down in a couple of different areas." He says someone likely made a programming or configuration mistake, but corporate culture could also be a factor. Often, he says, corporate security is underfunded or isn't given the authority it needs to make sure application developers do what's right.
Ryan Kalember of the security company Proofpoint says that even if the vulnerability was known and fixable, "coordination between app developers and security teams in a lot of organizations are not on the best of terms."
Equifax disclosed Thursday that a breach exposed personal information, including Social Security numbers, on 143 million Americans.