Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
mass-credential-exposurebreach-disclosure-notificationinternet-facing-service-vulnerabilitywidely-deployed-product-advisory

Equifax Breach Exposed Data on Nearly 148 Million People After Unpatched Apache Struts Flaw

Updated 28d agoFirst seen May 25, 202643 sources

Equifax disclosed that attackers exploited an unpatched Apache Struts vulnerability, CVE-2017-5638, in a public-facing dispute portal and stole highly sensitive consumer data including names, Social Security numbers, birth dates, addresses, and in some cases driver's license numbers and credit card data. Subsequent forensic reviews expanded the scope from the initial 143 million victims to roughly 145.5 million Americans, with later reporting putting the total at 147.7 million, while also identifying about 200,000 payment cards, 10.9 million driver's licenses, and smaller numbers of affected consumers in Canada and the UK. Government and media reporting said the attackers moved beyond the initial servers, accessed dozens of databases, and remained inside Equifax's network for weeks before discovery.

The breach drew intense scrutiny because the Struts flaw had been publicly disclosed and patched months earlier, yet Equifax failed to remediate it despite internal and external warnings about weak security. Reports described broader security shortcomings, including poor patching, outdated systems, weak logging, and a researcher warning that sensitive data was exposed on a public-facing site before the intrusion. Equifax's response also faced criticism after it delayed public disclosure, launched an unreliable breach-check website, and came under congressional examination over governance and accountability, while lawmakers and investigators pressed the company over how a preventable vulnerability led to one of the most damaging exposures of personal information in the United States.

Share:
Equifax Breach Exposed Data on Nearly 148 Million People After Unpatched Apache Struts Flaw
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

32 events from the most recent confirmed update back to the earliest known activity.

32 EVENTS
Oct 13, 20233y ago

UK FCA issues final notice and fine against Equifax Ltd

In 2023, the UK Financial Conduct Authority issued a final notice against Equifax Ltd over cybersecurity failures connected to the 2017 breach, imposing a financial penalty. This represents a distinct later-stage regulatory enforcement action in the UK beyond earlier disclosures and investigations already in the timeline.

Fca
Feb 10, 20206y ago

DOJ indicts four PLA officers for Equifax breach

On February 10, 2020, the U.S. Department of Justice charged four members of China’s People’s Liberation Army over the 2017 Equifax breach. Officials said the state-sponsored attackers stole personal data on about 147 million Americans as well as Equifax trade secrets and proprietary database information.

Chinese Military Officers Hacked Equifax, Justice Department Says - Defense One
Sep 16, 20197y ago

FTC-backed Equifax settlement draws backlash over $125 cash claims

By September 2019, criticism mounted over the Equifax breach settlement after officials acknowledged that the fund for cash payments was too small to cover large numbers of claims for the advertised up-to-$125 option. Consumers were urged to choose free credit monitoring instead, and claimants seeking cash were told to verify existing monitoring by October 15, 2019, or risk denial.

Opinion | Equifax Doesn’t Want You to Get Your $125. Here’s What You Can Do. - The New York Times
Jul 11, 20197y ago

Equifax reaches FTC-led global settlement over 2017 breach

Equifax agreed to a global settlement with the Federal Trade Commission, the Consumer Financial Protection Bureau, and 50 U.S. states and territories over the 2017 breach. The settlement provided for up to $425 million to help affected consumers, along with other relief and claims processes.

Equifax Data Breach Settlement | Federal Trade Commission
Sep 6, 20188y ago

Reported affected total rises to 147.7 million Americans

One year after the breach, reporting cited the incident as affecting 147.7 million Americans. This reflected a later upward revision of the overall impact beyond the 145.5 million figure disclosed in October 2017.

GAO details attacker movement, dwell time, and data theft scope

By September 2018, a Government Accountability Office report described how attackers moved from three compromised servers to 48 more, remained in Equifax's network for 76 days, and extracted data from 51 databases. The report also said Equifax declined DHS assistance during the response and instead relied on a private cybersecurity firm.

Mar 2, 20188y ago

Equifax says 2.4 million more Americans were affected

On March 2, 2018, Equifax disclosed that an additional 2.4 million U.S. consumers were impacted by the 2017 breach, raising the total to about 148 million. The company said it would directly notify the newly identified individuals and offer free identity theft protection and credit monitoring services.

Equifax says 2.4 million more Americans impacted by 2017 mega-breach | CyberScoop
Nov 28, 20179y ago

Equifax raises Canadian victim count to more than 19,000

On November 28, 2017, Equifax Canada said further investigation showed more than 19,000 Canadians were affected by the 2017 breach, up from the roughly 8,000 previously reported. The company also said 11,670 Canadian credit cards were affected and that exposed data included names, addresses, card details, and Social Insurance Numbers.

Equifax says more than 19,000 Canadians affected by security breach | CBC News
Nov 8, 20179y ago

Senate Commerce Committee holds new hearing on Equifax breach

On November 8, 2017, the U.S. Senate Commerce Committee held a hearing on consumer data security that included testimony from former Equifax CEO Richard Smith and interim CEO Paulino do Rego Barros Jr. Lawmakers questioned Equifax over the breach and the company said it was restructuring security oversight and developing an app for consumers to lock and unlock credit files.

Yahoo hack, Equifax data breach hearing: Richard Smith and Marissa Mayer will testify to Senate Commerce Committee
Oct 26, 20179y ago

Reporting reveals prior warning and broader security weaknesses

In late October 2017, reporting disclosed that Equifax had been warned months earlier about exposed sensitive data and vulnerable servers, and former employees described longstanding patching, logging, and legacy-system problems. The revelations suggested systemic security failures and possible multiple avenues of compromise.

Oct 11, 20179y ago

Equifax says 10.9 million driver's license records were compromised

By October 11, Equifax disclosed that attackers had obtained driver's license data for about 10.9 million Americans. This clarified the scale of one of the data categories only partially described in the initial breach notice.

Oct 10, 20179y ago

Equifax says 694,000 UK customers were affected

Equifax disclosed that about 694,000 UK customers were affected by the 2017 breach. The company said exposed UK data included phone numbers, driving licence details, and in some cases passwords and partial credit card information.

Equifax data hack affected 694,000 UK customers
Oct 4, 20179y ago

Congress examines Equifax breach in Senate hearing

US lawmakers held a Senate hearing on October 4, 2017, to examine the Equifax cybersecurity breach and the company's security failures and response. The hearing marked a major escalation in official scrutiny of the incident.

Oct 3, 20179y ago

House committee grills Equifax as former CEO blames employee error

On October 3, 2017, former Equifax CEO Richard Smith told the House Energy and Commerce Committee that the breach resulted from a single employee's failure to apply a critical patch, compounded by technology failures including a scanning tool that did not detect the issue. Lawmakers sharply criticized Equifax's security practices, breach response, and executive stock sales, escalating congressional scrutiny ahead of the Senate hearing.

Equifax Breach Caused by Lone Employee’s Error, Former C.E.O. Says - The New York Times
Oct 2, 20179y ago

Equifax reduces estimated Canadian victims to about 8,000

As part of the same October 2017 update, Equifax said Mandiant found no Equifax databases outside the United States were accessed and lowered the estimated number of affected Canadians from 100,000 to about 8,000. This materially revised the known international impact of the breach.

Equifax raises US victim count to 145.5 million

On October 2, Equifax said forensic review identified 2.5 million additional US consumers affected, increasing the total from 143 million to 145.5 million. The company said these were previously uncounted victims rather than a new intrusion.

Sep 26, 20179y ago

Equifax CEO Richard Smith retires after breach fallout

On September 26, 2017, Equifax announced the immediate retirement of CEO Richard Smith amid mounting criticism over the company's handling of the breach. Board member Mark Feidler was appointed non-executive chairman, and the board said it had formed a special committee to oversee the company's response and reduce the risk of a similar incident recurring.

Equifax chief Richard Smith steps down in wake of massive data breach | Business | The Guardian
Sep 19, 20179y ago

Equifax says about 100,000 Canadians may be affected

On September 19, 2017, Equifax Canada disclosed that about 100,000 Canadian consumers may have had personal information exposed in the broader breach, including names, addresses, Social Insurance Numbers, and in limited cases credit card data. The company said the data was accessed through a U.S. consumer website application and that Equifax Canada’s own systems and core credit-reporting databases were not directly compromised.

Equifax says 100,000 Canadians affected by cyberattack
Sep 14, 20179y ago

Equifax says 200,000 payment cards were exposed

Equifax disclosed that credit card numbers for about 200,000 US consumers were stolen from transaction history data. This added a new category of compromised information beyond the personal identity data already announced.

Equifax confirms unpatched Apache Struts flaw caused breach

On September 14, Equifax formally confirmed that attackers exploited the unpatched Apache Struts vulnerability CVE-2017-5638 to access its systems. The company said it was working with law enforcement, sharing indicators of compromise, and using Mandiant for incident response.

Sep 11, 20179y ago

New York attorney general opens investigation into Equifax breach

New York Attorney General Eric Schneiderman announced an investigation into Equifax following the company's breach disclosure. The move marked an early state-level official response to the incident amid mounting criticism of Equifax's handling of consumers' data.

Equifax's app has disappeared from Apple's App Store and Google Play - Fast Company
Sep 10, 20179y ago

Equifax says it will replace predictable credit-freeze PIN generation

Amid fallout from the breach, reporting revealed that Equifax generated credit-freeze PINs using a predictable method based on the date and time a freeze was created rather than random values. Equifax said it believed existing PINs were not compromised but would update the PIN generation and reset process to issue randomly generated PINs.

After Equifax Breach, Here’s Your Next Worry: Weak PINs - The New York Times

Equifax removes arbitration language from breach-response site terms

On September 10, 2017, Equifax updated its public statement to say consumers using its free breach-related credit monitoring and identity theft services did not waive their right to sue. The company said it removed arbitration language from the equifaxsecurity2017.com terms and would not enforce arbitration or class-action waiver provisions for claims tied to the incident or the free products.

What to know before you check Equifax Security 2017 data breach website - The Washington Post
Sep 8, 20179y ago

Equifax pulls mobile apps from Apple and Google app stores

In the week before September 15, 2017, Equifax removed its consumer mobile apps from the Apple App Store and Google Play. The company said the move was precautionary after identifying a vulnerability in the apps and amid concerns they could be used to compromise consumer information.

Here's Why Equifax Yanked Its Apps From Apple And Google Last Week - Fast Company

Equifax breach-response lookup tool draws criticism

Soon after the public disclosure, Equifax's online tool for checking whether consumers were affected was found to return inconsistent results, including for bogus inputs. The problems intensified criticism of the company's response and consumer communications.

Sep 7, 20179y ago

Equifax publicly discloses breach affecting 143 million people

Equifax announced the breach on September 7, 2017, saying attackers stole names, Social Security numbers, birth dates, addresses, and in some cases driver's license numbers for about 143 million consumers. The disclosure came more than five weeks after the company discovered the intrusion.

Aug 1, 20179y ago

Equifax executives sell stock after breach discovery

In the days following the July 29 discovery, three Equifax executives sold more than $1.8 million in stock. The sales drew scrutiny over the company's governance and incident handling.

Jul 29, 20179y ago

Equifax discovers the breach

Equifax discovered suspicious activity and identified the breach on July 29, 2017. Later reporting said attackers had remained in the environment for more than two months by that point.

Mar 10, 20179y ago

Attackers begin exploiting Equifax systems via unpatched Struts flaw

Equifax later said attackers breached its systems in May 2017 through an unpatched Apache Struts vulnerability in a US web application, commonly described as the dispute portal. The intrusion became the starting point of the company's major consumer data breach.

Mar 7, 20179y ago

Apache Struts flaw CVE-2017-5638 is publicly disclosed and patched

The Apache Struts vulnerability later tied to the Equifax breach was publicly disclosed and patched months before the intrusion. Later accounts said Equifax received a US-CERT alert about the flaw but failed to ensure the patch was applied.

Equifax takes down previously exposed website after warning

After months of inaction following the December researcher disclosure, Equifax removed the publicly exposed website in June 2017. Later reporting suggested this may have represented an additional avenue of compromise beyond the portal Equifax publicly blamed.

Researcher warns Equifax about exposed sensitive data and weak servers

An anonymous security researcher reported in December 2016 that an Equifax public-facing website exposed highly sensitive personal data without authentication and that multiple Equifax servers were vulnerable to basic attacks. According to later reporting, Equifax did not remove the exposed site until June 2017.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Equifax Breach Exposed Data on Nearly 148 Million People After Unpatched Apache Struts Flaw | Mallory