Breach report
Credit BureauEquifax
Giant Equifax data breach: 143 million people could be affected
Attackers exploited an unpatched flaw in an Equifax dispute portal and spent weeks pulling Social Security numbers and birth dates for nearly half of all Americans, triggering one of the largest breach settlements on record.
Reported by CNN
Records exposed
148M
About 147.9 million people
Scale vs. largest on file
- When
- 2017
- How they got in
- Exploitation of unpatched Apache Struts web vulnerability
- Sector
- Credit Bureau
In September 2017, Equifax, one of the three major U.S. credit reporting agencies, announced that hackers had accessed personal data on roughly 143 million Americans. Follow-up disclosures raised the total to about 147.9 million people, along with smaller numbers of consumers in the United Kingdom and Canada. The intrusion ran from mid-May through late July 2017, and Equifax said it discovered suspicious activity on July 29, roughly six weeks before telling the public.
The entry point was an online dispute portal running a version of the Apache Struts web framework with a known, critical vulnerability. A patch had been available since March 2017, but Equifax had not applied it on the affected system. Once inside, the intruders located unencrypted credentials that let them query dozens of databases, and an expired security certificate on a traffic-inspection tool meant the exfiltration went unnoticed for weeks.
The stolen data was among the most sensitive a consumer can lose: names, Social Security numbers, birth dates and addresses for nearly half the U.S. population, plus driver's license numbers for many. Credit card numbers for about 209,000 people and dispute documents with personal details for roughly 182,000 more were also taken. Because Social Security numbers cannot easily be changed, the exposure created long-term identity theft risk.
The company's response drew heavy criticism. Its breach-check website was initially hosted on a separate domain that looked like a phishing site, and executives who had sold shares before the disclosure faced scrutiny; one former executive was later convicted of insider trading. Chief executive Richard Smith retired within weeks, and the chief information and security officers also departed. In 2019, Equifax agreed to a settlement with the Federal Trade Commission, the Consumer Financial Protection Bureau and U.S. states worth up to about $700 million, including a consumer restitution fund. In February 2020, the Justice Department indicted four members of China's People's Liberation Army on charges of carrying out the hack.
The Equifax case remains a reference point for how a single missed patch can cascade into a national-scale breach. It pushed millions of Americans to freeze their credit files, a step that became free nationwide under a 2018 federal law, and it sharpened debate over how lightly regulated data aggregators handle information consumers never chose to share with them.