← Case Files · The Breach Files
Equifax, 2017: 147 million people, one unpatched web form
- People affected
- 147.9 million people
- When it happened
- 13 May – 29 July 2017
- Made public
- 7 September 2017
- How they got in
- Unpatched Apache Struts flaw (CVE-2017-5638) in a consumer dispute portal
- Attributed to
- Four members of China's PLA, indicted by the US Department of Justice in 2020
- What it cost
- Up to $700 million in settlements; the chief executive, CIO and CSO all left
What was exposed: Names · Social Security numbers · Dates of birth · Addresses · Driver's licence numbers · 209,000 credit card numbers
Equifax did not lose the data of its customers. It lost the data of people who had never heard of it — 147.9 million of them, about half the adult population of the United States, filed away by a company they had never chosen to deal with and could not opt out of. The intrusion lasted 76 days. The fix for the hole they came through had been available for two months before anyone walked through it.
What happened
On 6 March 2017, the Apache Software Foundation published a patch for CVE-2017-5638, a flaw in the Struts web framework that let an attacker run commands on a server simply by sending a malformed Content-Type header. It was about as serious as a web vulnerability gets: no credentials needed, no user interaction, full remote code execution. Exploit code was public within a day. The US Computer Emergency Readiness Team notified Equifax on 8 March, the company circulated an internal instruction to patch within 48 hours on 9 March, and a vulnerability scan on 15 March reported everything clean.
It was not clean. The scan had not reached the Automated Consumer Interview System — the public web portal where Americans went to dispute an error on their own credit report. ACIS was old, it was internet-facing, and it was running the vulnerable version of Struts. On 13 May, someone found it.
What followed was not a smash-and-grab. The intruders spent eleven weeks inside, and they were patient: they ran roughly 9,000 database queries, moved sideways into 48 unrelated databases, and pulled data out in small encrypted batches that looked like ordinary encrypted traffic. They found a file of unencrypted administrator credentials on a network share and used it to reach systems that had nothing to do with the dispute portal.
The detail that defines this breach. Equifax did inspect outbound traffic for exactly this kind of exfiltration. The device that did it needed a valid certificate to decrypt and read the traffic, and that certificate had expired ten months earlier, on 19 November 2016. On 29 July 2017 someone renewed it. The suspicious traffic appeared on screen the same day, and the intrusion was shut down within 24 hours. The monitoring worked. It had simply been switched off by neglect since the previous November.
How they got in
The chain is worth setting out step by step, because every link in it is ordinary:
- An internet-facing application nobody owned. ACIS was a legacy system with no clear owner and no accurate inventory entry, which is why the patch instruction and the scan both missed it.
- A framework vulnerability with public exploit code. CVE-2017-5638 required no skill to use by mid-March 2017. The window between patch and exploitation was 68 days.
- Flat internal networks. A foothold on a dispute portal should not reach 48 databases. There was no segmentation to stop it.
- Credentials in plaintext. A file of unencrypted usernames and passwords on an accessible share turned a limited foothold into broad access.
- Blind egress monitoring. The expired certificate meant 76 days of exfiltration passed a working detection system unread.
No zero-day, no insider, no nation-state tradecraft that an ordinary company could not have defended against. The 2020 indictment named four members of the People's Liberation Army's 54th Research Institute, and the techniques described in it are competent rather than exotic. The reason it worked was Equifax, not the attackers.
The timeline
- 6 March 2017 — Apache patches CVE-2017-5638.
- 8–9 March — US-CERT notifies Equifax; an internal patching instruction goes out.
- 15 March — A vulnerability scan fails to find the unpatched ACIS portal.
- 13 May — Intruders exploit the flaw and gain access.
- 13 May – 29 July — Around 9,000 queries across 48 databases; data leaves in encrypted batches.
- 29 July — An expired inspection certificate is renewed. The traffic becomes visible; access is cut off the next day.
- 1–2 August — Three senior executives sell shares worth around $1.8 million. Equifax later said they did not know of the breach; one, Jun Ying, was charged and pleaded guilty to insider trading.
- 7 September — Public disclosure: 143 million people. The figure is revised to 147.9 million in 2018.
- 26 September — Chief executive Richard Smith retires. The CIO and CSO had gone days earlier.
- 22 July 2019 — Settlement of up to $700 million with the FTC, CFPB and 50 states and territories.
- 10 February 2020 — The Department of Justice indicts four PLA members.
What was taken, and why it is permanent
Names, Social Security numbers, dates of birth and addresses for 147.9 million people. Driver's licence numbers for a smaller group. Credit card numbers for around 209,000. Around 15 million UK records and roughly 19,000 Canadian ones.
A card number can be cancelled in a phone call. A Social Security number cannot. It was never designed as a secret — it was an account number for a pension scheme — but the American financial system treats it as proof of identity, which means a stolen one stays useful for as long as the person it belongs to is alive. The same is true of a date of birth and a maiden name. The Equifax file is not a set of credentials that expire; it is a permanent identity kit for half a country, and it went into circulation in 2017 with no expiry date attached.
What happened next
The response made the breach worse. The lookup site Equifax set up for worried consumers ran on a lookalike domain rather than equifax.com — equifaxsecurity2017.com — which is precisely the pattern every bank tells customers to distrust. A security researcher registered a near-identical domain to make the point, and Equifax's own official Twitter account sent people to the fake one several times. The site's early answers were inconsistent: the same Social Security number could return different results on different attempts. The offer of free credit monitoring initially carried terms that appeared to waive the right to sue, which the company withdrew after a public outcry.
The settlement two years later was worth up to $700 million, including a $425 million fund for consumers. The FTC had to publicly warn claimants that the advertised $125 cash alternative would be reduced to a token amount, because far more people claimed it than the fund could pay. For most people the practical outcome of the largest consumer data settlement in US history was a few dollars or a few years of monitoring they had to remember to enrol in.
What it changed
Three things, none of them the one people expected.
First, credit freezes became free. Before Equifax, the bureaus charged consumers a fee to lock down a credit file the consumer had never asked them to compile. US federal law made freezes and unfreezes free nationwide from September 2018 — a direct consequence of the political fallout.
Second, patching timelines stopped being an internal matter. Regulators now ask how long a known critical vulnerability stood unpatched on an internet-facing system, and "we sent an email" is not an answer. The asset inventory question — do you actually know what you are running? — moved from a tick-box to the first question asked after any incident.
Third, certificate expiry became an operational risk category rather than an annoyance. An expired certificate that takes a website offline is embarrassing and gets fixed in an hour. An expired certificate that quietly blinds a monitoring system generates no alert at all, and Equifax is the reason that scenario is now on the list.
If you were in it
There is no remediation for a leaked Social Security number, only mitigation, and the mitigation is unglamorous:
- Freeze your credit at all three bureaus — Equifax, Experian and TransUnion. It is free, it takes about ten minutes each, and it blocks the specific fraud this data enables: someone opening credit in your name. Unfreeze temporarily when you actually apply for something.
- Assume identity-verification questions are compromised. Your date of birth, previous addresses and the name of your first street are in this file. Where a service offers a stronger option than knowledge-based verification, take it.
- Expect the phone calls. Data this rich is what makes a scam call convincing. A caller who already knows your address and the last four of your Social Security number has not proved they are your bank; they have proved they have the file.
- Check your own exposure across other breaches too. Equifax was one file among many, and the ones that carry your reused passwords are the ones an attacker will try first — see how to check an email address against known breaches.
Questions people ask
Was I affected by the Equifax breach?
If you have ever had credit in the United States, assume yes — 147.9 million people is roughly half the US population, and nobody in the file ever chose to be Equifax's customer. Equifax ran a lookup tool after the breach, though its answers were unreliable in the first weeks. The more useful assumption is that your Social Security number is already circulating, and to act accordingly with a credit freeze.
What data was stolen in the Equifax breach?
Names, Social Security numbers, dates of birth and addresses for 147.9 million people; driver's licence numbers for a smaller subset; and credit card numbers for around 209,000 people. Roughly 15 million UK records and around 19,000 Canadian records were also taken.
Did anyone go to prison over the Equifax breach?
Not for the breach itself. Jun Ying, a former chief information officer at Equifax's US Information Solutions unit, pleaded guilty to insider trading for dumping his shares before the public announcement and was sentenced in 2019. In 2020 the Department of Justice indicted four members of China's People's Liberation Army over the intrusion; they are not in US custody.
How much did Equifax pay?
The 2019 settlement with the FTC, the CFPB and 50 US states and territories was worth up to $700 million, including a $425 million consumer restitution fund. Individual payouts were small: the fund was heavily oversubscribed and cash claims of $125 were cut to a few dollars each.
Sources
- US Government Accountability Office, GAO-18-559: Actions Taken by Equifax and Federal Agencies in Response to the 2017 Breach — the clearest public account of the intrusion
- Federal Trade Commission — Equifax data breach settlement
- US Department of Justice indictment of four PLA members, February 2020
- US Senate Permanent Subcommittee on Investigations report, 2019
Read next
Case files are written from the public record: regulatory findings, court filings, company disclosures and contemporaneous reporting, cited above. Figures are the ones the organisation or its regulator finally settled on, which is often not the number first reported — where that differs, the page says so. Disputed accounts are marked as disputed rather than resolved in either direction.