The encyclopedia · Software & IT · Technical decision · 2017
Equifax left a known software flaw unpatched — and exposed the data of 147 million people
In 2017 credit bureau Equifax revealed a breach exposing the personal data of about 147 million people. The cause was an unpatched software flaw it had failed.
Equifax · 2017-09-07
What happened
Equifax is one of the three major US credit bureaus, holding the personal and financial data of hundreds of millions of people. In 2017 it disclosed one of the largest data breaches in history: attackers had exploited a known vulnerability in Apache Struts, a piece of web software, to access the personal data of about 147 million people — Social Security numbers, birth dates, addresses and, in some cases, driver's license numbers and credit card details.
The most damning detail was that the vulnerability was not unknown. A patch had been available months before the breach, but Equifax had failed to apply it across its systems. The attackers moved through the network undetected for weeks, and the company's failure to detect and contain the intrusion compounded the damage.
The fallout was severe. Equifax's chief executive, Richard Smith, resigned. The company agreed to a settlement of up to $700 million, including compensation to affected consumers and penalties, and it faced congressional hearings and lasting damage to its reputation. The breach became a landmark case in cybersecurity — a stark example of how a failure to apply a known, available patch can expose the most sensitive data of nearly half a country.
Why it happened
- Equifax failed to apply a known, available patch to a software vulnerability (Apache Struts) for months, leaving the door open.
- Attackers exploited the unpatched flaw and moved through the network undetected for weeks.
- As a credit bureau, Equifax held the most sensitive personal data of hundreds of millions of people, so the breach was catastrophic.
- Weak detection and slow response let the intrusion persist and the damage grow before it was discovered.
The lesson
A known vulnerability with an available patch is not a risk to be managed later — it is an open door. Equifax held the most sensitive data of 147 million people and failed to apply a patch that had.
Aftermath
The Equifax breach is one of the most cited cases in cybersecurity, a landmark example of how a failure to apply a known patch can expose the most sensitive data of nearly half a country. It led to a settlement of up to $700 million, the resignation of the CEO, congressional hearings, and lasting reforms in how companies handle data security and breach disclosure. The lesson is durable: the most damaging breaches are rarely caused by unknown 'zero-day' exploits — they are caused by known flaws that someone failed to fix, and the data you hold is a responsibility, not just an asset.
Sources
- FTC — 'Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach', 22 July 2019
- 2017 Equifax data breach — Wikipedia (147M exposed, unpatched Apache Struts, $700M settlement)
spotted an error? The club wants to know.
More like this
A bad CrowdStrike update blue-screened 8.5M Windows PCs in the biggest IT outage ever
Facebook locked itself out of the internet for six hours with one bad maintenance command
Allianz Life's CRM vendor door exposed most of its 1.4M customers
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.