The Equifax Data Breach and the Cost of Basic Security Failure

A missed patch exposed identity data that millions of people could not easily replace, at a company they never meaningfully chose to trust.

We may earn affiliate commissions from links on this page. Learn more.

Cyber Altitude Guide

Online Safety Starter Kit

Start with the basics for safer accounts, devices and everyday browsing.

Lock down accounts

Strong passwords, a password manager, MFA and email aliases.

Secure devices and files

Block malware, avoid risky downloads and back up important files.

Browse with less exposure

VPN, secure DNS and private browsing tools on risky networks.

Most of the people caught in the Equifax data breach had never opened an account with Equifax. They had borrowed money, rented a flat or applied for a credit card, and somewhere inside those ordinary transactions their details arrived at a company they had not chosen. In 2017 that company lost them. Roughly 147 million people had names, Social Security numbers, birth dates and addresses exposed, in one of the largest losses of identity data in United States history.

The 2017 Equifax data breach did not begin with anything sophisticated. It began with a flaw in a widely used piece of web software, a published fix that had been available for more than two months, and a patch that never reached the one system that needed it.

That contradiction is why the breach is still worth studying. A basic security failure produced unusually long-lived consequences, because of what Equifax held and how little say the people described in those records had over whether the company held anything about them at all.

The Data People Never Chose to Give Equifax

Equifax is a consumer reporting agency, one of the three nationwide companies that assemble credit files on American consumers. Lenders, card issuers and other data furnishers send it account and payment information. Equifax compiles that into reports and scores, and other institutions use them when deciding whether to approve a loan, rent out a property or, in some cases, make a job offer.

Nobody signs up for this. A person can have an Equifax credit file without ever visiting the company’s website, because the file is built from what lenders report rather than from anything the consumer submits. The Government Accountability Office later stated the consequence plainly: consumers generally cannot choose which nationwide credit reporting agencies maintain their information, and they have no legal right to remove themselves from the consumer-reporting system.

Why Equifax Had Information About People Who Never Signed Up
A credit file is built from what lenders report, not from anything the consumer fills in. Banks, card issuers and other data furnishers send account and payment information to the nationwide consumer reporting agencies, so an Equifax file can exist for someone who has never visited the company. Consumers can see, dispute and freeze that file. They cannot decline to have one.

That is not the same as having no rights at all. People can see their files, dispute what is in them and freeze access to them. What they cannot do is decline to participate.

The arrangement concentrated an enormous quantity of identity data inside one company, and that company ran a complex environment built up over years of expansion, still containing legacy systems. House investigators later linked that complexity to its security risk. Whatever the merits of the credit-reporting model, it placed an obligation on Equifax that the people affected by it had no way to shop around for. In March 2017 a vulnerability appeared that would test how well the company met it.

How the Equifax Data Breach Happened

The vulnerability was not Equifax’s own. On March 7, 2017, the Apache Software Foundation disclosed a critical flaw in Apache Struts, tracked as CVE-2017-5638, and released fixed versions. The flaw allowed remote code execution, meaning that anyone able to reach an affected web application could run commands on the server behind it. The Department of Homeland Security alerted Equifax the next day.

The company’s own process moved. On March 9 its vulnerability-management team emailed more than 400 employees, instructing the owners of affected Struts systems to patch within 48 hours. A meeting about the vulnerability followed on March 16. The Automated Consumer Interview System, an online portal where consumers filed disputes about their credit files, stayed unpatched through all of it.

Attackers began exploiting that portal on May 13, more than two months after the fix had been published. Inside the application they found credentials stored without encryption, and those credentials opened the way into other parts of the environment. Congressional investigators later found the attackers reached 48 additional databases. One unpatched web application had become a route into a far larger store of consumer information.

The Patch Existed Before the Attack
March 7, 2017: Apache discloses the Struts flaw and releases fixed versions. March 9, 2017: Equifax instructs affected system owners to patch within 48 hours. May 13, 2017: Attackers begin exploiting the still-unpatched portal.

Why Nobody Noticed for 76 Days

The attackers stayed for 76 days, and the reason they went unseen is almost mundane. A device that inspected encrypted network traffic on that system had been running with a certificate that expired 19 months earlier. Encrypted traffic passed through it uninspected, so the data leaving the environment did not register as anything at all.

Equifax replaced the certificate on July 29. Suspicious traffic appeared immediately, the portal was taken offline the following day, and on August 2 the company retained Mandiant for a forensic investigation and contacted the FBI. The expired certificate did not cause the breach. It is the reason a two-and-a-half-month intrusion was invisible while it was happening.

When the Breach Became a Consumer Trust Crisis

Equifax disclosed the breach publicly on September 7, 2017, six weeks after taking the portal offline. The announcement put the number of potentially affected U.S. consumers at approximately 143 million, close to half the adult population of the country.

The company set up a website where people could check whether they were affected, and it did not hold up. Congressional investigators later described a response overwhelmed by demand, with call centers unable to handle the volume and consumers unable to get a clear answer about their own exposure. That uncertainty was its own kind of harm. Someone who could not establish whether their Social Security number had been taken also could not decide what to do about it.

Equifax’s chief information officer and chief security officer left on September 15, and chief executive Richard Smith departed later that month. Congressional committees opened investigations and regulators followed. A security incident at a company most Americans could not have described a month earlier had become a national story.

The number kept moving. An October forensic review raised the U.S. figure to 145.5 million. In March 2018 Equifax identified roughly 2.4 million more people whose names and partial driver’s-license details had been stolen, producing the total now generally cited as about 147 million. Each revision was more accurate than the one before it. Each also reminded people that the company describing the damage was still working out how large it was.

What Data Was Stolen in the Equifax Breach?

The categories matter more than the headline figure, because they are not all the same size. Equifax’s May 2018 filing broke them out: roughly 146.6 million names and dates of birth, 145.5 million Social Security numbers and 99 million address records. Around 209,000 payment-card numbers were taken, along with about 182,000 dispute documents containing personal information.

So the often-repeated claim that 147 million Social Security numbers were stolen is close, but not correct. The affected population and the Social Security number count are different figures, and the payment-card subset is smaller than both by three orders of magnitude. What matters is which categories dominate. The information taken in the largest volumes was the information people use to prove who they are.

Not All Stolen Data Can Simply Be Changed
A password can be reset. A payment card can be cancelled and reissued. A date of birth cannot be changed at all, and the Social Security Administration issues a new number only in limited circumstances, such as continuing disadvantage from identity theft after someone has already tried to resolve it. That is why exposure of identity data creates risk on a different timescale from a credential breach.

What Equifax Revealed About Data People Cannot Escape

Most security incidents produce work. A password gets changed, a card is cancelled and reissued, an account is locked and recovered. The loss is real and the remedy is available, and within a week or two the stolen thing no longer exists in the form the attacker took.

Identity data does not behave that way. A date of birth cannot be changed. An address history is a matter of record. The Social Security Administration assigns a new number only in limited circumstances, such as continuing disadvantage from identity theft after someone has already tried to resolve it, so for almost everyone whose number sat in those files, the exposed number is still their number today.

That is why the consequences ran long. Credit monitoring, the standard remedy offered after the breach, watches for misuse rather than preventing exposure. It is a reasonable response to a problem that cannot be undone, and it is also an admission that the problem cannot be undone. The data was not recovered or invalidated. It entered circulation, and nothing since has taken it back out.

The Failure Was Bigger Than One Missed Patch

It would be tidy to say Equifax failed to install one patch, and the investigations do not support that reading. GAO identified four contributing factors: identification, detection, database segmentation and data governance. The unpatched portal was the first of them, not the whole account.

Each additional weakness widened what the first one cost. Credentials stored without encryption turned application access into database access. Weak segmentation left 48 databases within reach of a compromised dispute portal.

An expired certificate meant nobody saw the traffic leaving. The FTC alleged in its complaint that the company had failed to take reasonable steps to secure its network, citing patching, segmentation and intrusion-detection problems. House Oversight majority staff went further and concluded the breach was entirely preventable, which is that committee’s majority conclusion rather than a neutral finding.

A preventable security failure exposed durable identity data held on people who had little ability to choose whether Equifax collected or maintained it. The institution controlled the data. The people described in it carried the consequences, for years, with no version of the problem they could solve themselves.

What Changed After the Equifax Data Breach

The scrutiny was immediate and it lasted. Congressional committees investigated, GAO reviewed both the breach itself and the wider oversight of consumer reporting agencies, and the FTC and CFPB opened investigations of their own. Equifax replaced senior leadership, increased security spending and worked through remediation. Federal agencies that bought services from the company reassessed its controls and modified their contracts.

The Equifax data breach settlement arrived on July 22, 2019. The company reached a global agreement with the FTC, the CFPB and the states and territories providing at least $575 million, rising to as much as $700 million if consumer claims required it. Up to $425 million was designated for consumer relief and $100 million was a civil penalty paid to the CFPB. The agreement also imposed ongoing security obligations rather than money alone.

Consumer protections changed over the same period. Federal law made credit freezes and unfreezes free nationwide from September 21, 2018, and extended fraud alerts to a full year. That law followed a stretch of heightened public concern about data breaches and identity theft, of which Equifax was the most visible example. The breach intensified the pressure behind it. It did not produce the law on its own.

Attribution came last. In February 2020 U.S. prosecutors charged four members of China’s People’s Liberation Army, alleging they carried out the intrusion and stole personal data along with trade secrets. Those are charges rather than convictions. They also answer only who is alleged to have taken the data, and change nothing about how it was reachable in the first place.

Why Credit Data Is Still a Weak Point

Some things are better now. Credit freezes are free and quick to place, consumers have easier access to their files, and identity-restoration support has become a normal part of how large breaches are handled. Equifax operates under security obligations it did not have in 2017, and consumer reporting agencies draw more regulatory attention than they used to.

The arrangement underneath has not moved. Creditors still report account information to consumer reporting companies, and the CFPB’s current guidance is blunt about what that means for the individual: you cannot opt out of it. Identity data remains concentrated in a small number of companies, and a person who has lost confidence in one of them still cannot take their file elsewhere.

This is where Equifax marks the boundary of what personal security can reach. Unique passwords, a password manager, multi-factor authentication, an updated device and a careful browser setup all shrink the surface an attacker can get at through you.

None of them touches information a lender already reported to a credit bureau. You can do everything correctly on the risks you control and still be exposed through an institution you never chose, which is the part of online safety that individual habits cannot cover.

The Equifax data breach still matters because people remain dependent on institutions holding identity information they cannot withdraw, and personal cybersecurity does not protect data already stored elsewhere. The same problem extends beyond credit bureaus wherever sensitive information is concentrated inside institutions people cannot easily avoid.

The Trust Problem Equifax Left Behind

The breach was preventable, which is the part that stays uncomfortable. A fix existed. A warning arrived. An internal instruction went out. The system that mattered was missed anyway.

What made the cost unusual was not the number of people involved but the nature of what they lost and how little say they had in the arrangement that lost it. Information was gathered about them, held so that they could be assessed by it, and exposed without their participation at any stage.

Equifax’s lasting lesson is that data becomes a security responsibility long before the person it describes has any meaningful choice about where it is kept.