Back to the archive

The encyclopedia · Software & IT · Technical decision · 2017

Equifax left a known software flaw unpatched — and exposed the data of 147 million people

In 2017 credit bureau Equifax revealed a breach exposing the personal data of about 147 million people. The cause was an unpatched software flaw it had failed.

Equifax · 2017-09-07

What happened

Equifax is one of the three major US credit bureaus, holding the personal and financial data of hundreds of millions of people. In 2017 it disclosed one of the largest data breaches in history: attackers had exploited a known vulnerability in Apache Struts, a piece of web software, to access the personal data of about 147 million people — Social Security numbers, birth dates, addresses and, in some cases, driver's license numbers and credit card details.

The most damning detail was that the vulnerability was not unknown. A patch had been available months before the breach, but Equifax had failed to apply it across its systems. The attackers moved through the network undetected for weeks, and the company's failure to detect and contain the intrusion compounded the damage.

The fallout was severe. Equifax's chief executive, Richard Smith, resigned. The company agreed to a settlement of up to $700 million, including compensation to affected consumers and penalties, and it faced congressional hearings and lasting damage to its reputation. The breach became a landmark case in cybersecurity — a stark example of how a failure to apply a known, available patch can expose the most sensitive data of nearly half a country.

Why it happened

  • Equifax failed to apply a known, available patch to a software vulnerability (Apache Struts) for months, leaving the door open.
  • Attackers exploited the unpatched flaw and moved through the network undetected for weeks.
  • As a credit bureau, Equifax held the most sensitive personal data of hundreds of millions of people, so the breach was catastrophic.
  • Weak detection and slow response let the intrusion persist and the damage grow before it was discovered.
What it cost147M exposed; up to $700M settlement; CEO outcostly

The lesson

A known vulnerability with an available patch is not a risk to be managed later — it is an open door. Equifax held the most sensitive data of 147 million people and failed to apply a patch that had.

Aftermath

The Equifax breach is one of the most cited cases in cybersecurity, a landmark example of how a failure to apply a known patch can expose the most sensitive data of nearly half a country. It led to a settlement of up to $700 million, the resignation of the CEO, congressional hearings, and lasting reforms in how companies handle data security and breach disclosure. The lesson is durable: the most damaging breaches are rarely caused by unknown 'zero-day' exploits — they are caused by known flaws that someone failed to fix, and the data you hold is a responsibility, not just an asset.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →