Equifax Data Breach (Jul-Sep 2017)
Introduction
In September 2017, Equifax — one of the three major US credit-reporting agencies — disclosed that its systems had been breached between May and July of that year. The exposed data covered 147.9 million Americans: Social Security numbers, dates of birth, home addresses, and in some cases driver's licence numbers and payment card details. The breach was not the result of a novel attack. It exploited a known, patchable vulnerability in Apache Struts (CVE-2017-5638) for which a patch had been publicly available since 8 March 2017 — more than two months before the breach began.
The Equifax breach is catalogued here as a confirmed case of institutional negligence compounded by insider trading and delayed disclosure — not because it involves fabricated claims, but because the documented facts are themselves more damaging than most conspiracy theories about corporate misconduct.
The Vulnerability and the Patch
Apache Struts is a widely-used open-source web application framework. CVE-2017-5638, published in the National Vulnerability Database on 8 March 2017, described a remote code execution vulnerability that allowed attackers to execute arbitrary commands on a server via a malformed HTTP header. The US Computer Emergency Readiness Team (US-CERT) issued alerts the same day. Equifax's internal security team was notified of the required patch. The patch was not applied to all systems.
On 13 May 2017 — 66 days after the patch was available — attackers began exploiting the unpatched vulnerability in Equifax's ACIS (Automated Consumer Interview System) dispute portal. The breach continued for 78 days before Equifax's security team detected it on 29 July 2017.
The Disclosure Timeline
Equifax discovered the breach on 29 July 2017. It did not notify the public until 7 September 2017 — 40 days after discovery. During that 40-day window:
- Chief Financial Officer John Gamble sold $946,374 in shares on 1 August 2017
- President of US Information Solutions Joseph Loughran sold $584,099 in shares
- President of Workforce Solutions Rodolfo Ploder sold $250,458 in shares
The company initially attributed these sales to pre-arranged trading plans. The Department of Justice subsequently charged former CIO Jun Ying with insider trading for selling approximately $950,000 in options in August 2017 after learning the company whose systems were breached was Equifax. Ying was convicted in 2019 and sentenced to four months in prison. Former manager Sudhakar Bonthu was also charged; he pleaded guilty and was sentenced to eight months of home confinement.
Executive Accountability
CEO Richard Smith appeared before multiple congressional committees in early October 2017, testifying that the failure to patch was the result of a breakdown in Equifax's internal security patching process: a single individual had failed to implement the scan that would have identified the vulnerable system. Smith resigned on 26 September 2017. CIO David Webb and CSO Susan Mauldin resigned on 26 September 2017 as well.
Critics noted that Mauldin held degrees in music composition rather than information security — a detail that became a flashpoint in congressional hearings about the adequacy of Equifax's security leadership. Equifax disputed characterisations of Mauldin's qualifications as misleading.
The Settlement and Regulatory Response
In July 2019, Equifax settled with the Federal Trade Commission, the Consumer Financial Protection Bureau, and all 50 state attorneys general for $700 million — at the time the largest data-breach settlement in US history. The settlement included up to $425 million in consumer restitution, though actual per-consumer payouts were significantly lower than initially advertised due to the volume of claims. The FTC was criticised for the settlement terms.
What the Breach Confirmed
The Equifax breach is a confirmed case of institutional negligence — a known critical vulnerability, unpatched for over two months, on a system holding the financial identity data of almost half the US adult population. The subsequent insider trading by executives who sold stock with advance knowledge of the breach compounds the institutional failure with documented financial crime.
No fabricated claims are involved. The documented record is the story.
Verdict
Confirmed. Every major element — the unpatched CVE, the 78-day undetected breach, the 40-day delayed disclosure, the pre-disclosure stock sales, the insider trading charges and convictions — is documented in court records, congressional testimony, FTC filings, and contemporaneous journalism. The breach is one of the most consequential failures of corporate data stewardship in US history.
The GAO's Independent Audit
In August 2018, the Government Accountability Office — Congress's independent auditor — published GAO-18-559, "Data Protection: Actions Taken by Equifax and Federal Agencies in Response to the 2017 Breach." The report was publicly released on 7 September 2018, a year to the week after Equifax's original disclosure. GAO's investigators, working independently of both Equifax and the congressional committees, identified four distinct categories of failure rather than a single patching lapse: weaknesses in identification of the vulnerable system, weaknesses in detection of the intrusion once it began, inadequate segmentation of databases from one another, and weak data governance practices generally. GAO noted that the CFPB and FTC investigation was still open at the time of publication and explicitly declined to issue new recommendations, deferring to two follow-on reports on credit-reporting-agency oversight and consumer privacy. The GAO's contribution to the record is significant precisely because it is not an accountability document — it is a systems audit, and it found the patch failure was one symptom of a broader architectural problem, not an isolated human error.
The House Oversight Committee's Findings
Three months after the GAO report, on 10 December 2018, the majority staff of the House Committee on Oversight and Government Reform released its own report after a 14-month investigation that reviewed more than 122,000 pages of documents and interviewed current and former Equifax employees alongside Mandiant, the forensic firm Equifax had retained. The Committee's headline conclusion was that the breach was "entirely preventable." Two findings from that report go beyond what is already documented in this entry's main narrative. First, Equifax's intrusion-detection system had been unable to inspect encrypted traffic for 19 months because the digital certificate needed to decrypt and monitor that traffic had expired and was not renewed — meaning the attackers' exfiltration of data over 78 days occurred inside a blind spot Equifax itself had created and failed to notice. Second, the Committee found a structural governance defect: Equifax's Chief Security Officer reported not to the Chief Information Officer, the executive responsible for the systems the CSO was meant to secure, but to the company's legal department. The Committee described this as an accountability gap between the people who set security policy and the people who implemented it.
The 2020 Indictment: Naming Chinese Military Hackers
On 10 February 2020, the Department of Justice unsealed an indictment charging four members of China's People's Liberation Army — Wu Zhiyong, Wang Qian, Xu Ke, and Liu Lei — with the intrusion. All four were identified as members of the PLA's 54th Research Institute. The nine-count indictment alleged conspiracy to commit computer fraud, computer fraud and abuse with intentional damage to a protected computer, conspiracy to commit economic espionage, economic espionage, conspiracy to commit wire fraud, and wire fraud. Attorney General William Barr, announcing the charges, said the intrusion was "a deliberate and sweeping intrusion into the private information of the American people," and added that the stolen data "has economic value, and these thefts can feed China's development of artificial intelligence tools as well as the creation of intelligence-targeting packages." Investigators said they identified the four defendants through forensic analysis of the malware used and the attackers' infrastructure, despite the hackers' use of encrypted communications and traffic routed through servers in roughly 20 countries to obscure their tracks.
What the Indictment Does Not Prove
An indictment is a set of criminal charges, not a verdict. None of the four PLA officers has ever been in US custody, and officials acknowledged at the time of the announcement that there is little realistic prospect of any of them appearing in an American courtroom: the United States has no extradition treaty with China. The practical effect of the indictment is to put the defendants on notice that they risk arrest if they travel outside China, and to formally attribute the intrusion for diplomatic and legal purposes — not to subject the underlying evidence to adversarial testing in open court. Writing in Foreign Policy, Brookings fellow Robert Williams argued the broader US strategy of indicting state-linked hackers who will never be tried has a mixed record as deterrence: "China's state-sponsored cybertheft has not meaningfully diminished in response to the U.S. indictment campaign" since the practice began in 2014, he wrote, suggesting the indictments may serve legal or diplomatic purposes — such as laying groundwork for sanctions or offensive cyber responses — that are distinct from, and narrower than, stopping the underlying activity. This entry treats the PLA attribution as the official, charged US government position — supported by forensic investigation — while noting that it rests on prosecutorial allegation rather than a adversarially-tested criminal conviction, unlike the Jun Ying insider-trading case, which did result in a guilty plea.
Beijing's Denial
China's government rejected the accusation. The day after the indictment was unsealed, foreign ministry spokesperson Geng Shuang told reporters that China "firmly oppose[s] and combat[s] cyberattacks of any kind" and that "the Chinese government, military and relevant personnel never engage in cyber-theft of trade secrets," while turning the accusation back on Washington by citing the WikiLeaks and Snowden disclosures as evidence of American "hypocrisy and double standards." No independent, non-governmental forensic body has published a competing attribution; the denial is a diplomatic statement, not a rebuttal supported by published counter-evidence.
The Settlement's Contested Adequacy
The $700 million July 2019 settlement was widely reported as historic, but its consumer-facing terms drew sustained criticism. The FTC had advertised that affected consumers could choose a $125 cash payment in lieu of credit monitoring. Only $31 million was allocated to the cash-payment option. When far more than 31 million dollars' worth of consumers chose cash, the FTC walked the number back: deputy director Peter Kaplan said in July 2019 that payouts would be divided among all claimants and would likely be "nowhere near" $125 per person. Senator Elizabeth Warren asked the FTC's Inspector General to investigate the agency's own public statements as potentially misleading, and the consumer group Demand Progress called on the FTC to issue itself a cease-and-desist for what it called an empty promise. Separately, in December 2019 a federal court approved close to $80 million in fees for the consumer class-action attorneys in the parallel private litigation — a detail critics have cited when arguing the settlement's structure served litigants and lawyers more predictably than it served the 147 million people whose data was actually exposed.
Executive Compensation After the Breach
Richard Smith agreed to forgo his 2017 bonus, reportedly worth several million dollars. He was not, however, required to forfeit the bulk of his compensation: reporting after his departure put his retained stock and pension benefits at roughly $18–24 million, on top of lifetime medical coverage. Equifax's clawback policy at the time only applied to compensation tied to accounting fraud, not to losses stemming from a security failure or a regulatory settlement, so none of Smith's pay was clawed back. This is a governance detail rather than evidence of a conspiracy: it shows an incentive-structure gap that predates and is independent of the breach, and it applied automatically rather than through any documented decision to shield Smith specifically.
Distinguishing Insider Trading from a "Corporate Cover-Up"
It is worth being precise about what was and was not charged. Jun Ying and Sudhakar Bonthu were prosecuted and either convicted or pleaded guilty to personal insider-trading offenses — using material nonpublic information for individual financial gain. Neither the SEC nor the DOJ ever alleged, let alone charged, a board-authorized or company-wide scheme to conceal the breach for collective benefit; the three executives whose August 2017 stock sales drew scrutiny (CFO John Gamble, and division presidents Joseph Loughran and Rodolfo Ploder) were never charged criminally, and Equifax's own internal review concluded their sales were made under pre-existing trading plans. A version of this story that frames the stock sales as proof of an orchestrated corporate cover-up goes beyond what has been charged or proven; the version supported by the documented record is narrower — a company-wide security failure, compounded by two individual employees who used what they knew for personal profit, that in Ying's case was substantial enough to secure a criminal conviction.
What Remains Unresolved
Taken together, the GAO audit, the House Oversight report, the 2020 indictment, and the disputed settlement do not change the confirmed verdict on this breach — if anything they deepen the documented record of institutional failure. But they also mark the edges of what is actually proven: state attribution that rests on an untested indictment rather than a conviction, a settlement whose consumer remedy was mismatched to an espionage-motivated theft rather than a financially-motivated one, and individual criminal liability that stopped well short of the company's boardroom.
Evidence Filters17
CVE-2017-5638 patch available 8 March 2017 — breach began 13 May 2017
SupportingStrongThe Apache Struts vulnerability exploited in the Equifax breach had a publicly available patch 66 days before the breach began. US-CERT issued alerts the same day as the patch release. Equifax's security team was notified. The failure to apply the patch is documented in congressional testimony by CEO Richard Smith.
78-day undetected breach period
SupportingStrongFrom 13 May to 29 July 2017, attackers exfiltrated data for 78 days without detection. This duration is evidence of inadequate monitoring and detection capabilities relative to the sensitivity of the data Equifax held.
Executives sold $1.8M in stock between discovery and public disclosure
SupportingStrongCFO John Gamble, Joseph Loughran, and Rodolfo Ploder sold a combined $1.8 million in shares between 29 July 2017 (discovery) and 7 September 2017 (public disclosure). The company attributed the sales to pre-arranged trading plans.
Rebuttal
The company's claim that the sales were pre-arranged trading plans under 10b5-1 programmes was accepted as an explanation for most of the executives' trades. The DOJ pursued charges only against Jun Ying and Sudhakar Bonthu, not the CFO or the two presidents.
Jun Ying convicted of insider trading — sentenced to four months
SupportingStrongFormer Equifax CIO Jun Ying was charged by the DOJ with insider trading for selling approximately $950,000 in stock options in August 2017 after learning his company was the breach victim. He was convicted at trial in 2019 and sentenced to four months in prison and $117,117 in disgorgement.
$700M FTC and state AG settlement — largest data breach settlement at the time
SupportingStrongIn July 2019 Equifax settled with the FTC, CFPB, and all 50 state attorneys general for $700 million, including up to $425 million in consumer restitution. It was the largest data breach settlement in US history at the time of announcement.
CEO, CIO, and CSO all resigned 26 September 2017
SupportingRichard Smith (CEO), David Webb (CIO), and Susan Mauldin (CSO) all departed on 26 September 2017. The simultaneous resignation of the top security and technical leadership was widely interpreted as accountability for the breach and the response.
Consumer restitution payouts far below advertised amounts
NeutralThe FTC's initial advertising of up to $125 per consumer was criticised when the volume of claims made clear the actual per-person payout would be far smaller. The FTC updated guidance to recommend consumers take credit monitoring services instead of cash payouts.
Rebuttal
The settlement cap was $425M for consumer restitution. With 147.9M potential claimants and high claim volume, per-consumer cash payouts were inevitably small. The FTC's communications around the settlement were criticised as misleading by consumer advocates.
Congressional testimony attributed patch failure to a single individual
NeutralCEO Richard Smith testified before Congress that the failure to apply the patch resulted from a breakdown in Equifax's internal scanning process — one individual had failed to run the scan that would have identified the vulnerable system. Critics argued this deflected institutional accountability onto a single employee.
Rebuttal
Attributing a systemic failure in patch management to a single individual's error was widely criticised by security professionals as a deflection from institutional governance failures. Patch management processes should not depend on a single point of failure.
GAO-18-559 identified four systemic causes, not just an unpatched vulnerability
SupportingStrongThe Government Accountability Office's August 2018 report (GAO-18-559) found the breach resulted from documented weaknesses across four areas: identification of at-risk systems, detection of the intrusion, database segmentation, and data governance — an independent congressional audit corroborating that the failure was architectural, not a single missed patch.
House Oversight report found an expired security certificate blinded intrusion detection for 19 months
SupportingStrongThe House Oversight Committee's December 2018 report found Equifax's intrusion-detection system could not inspect encrypted traffic for 19 months because a required digital certificate had expired and was not renewed, and that the Chief Security Officer reported to the legal department rather than the CIO — a documented structural accountability gap beyond the single missed-scan explanation given in 2017 congressional testimony.
Show 7 more evidence points
The four indicted PLA officers were never tried, and are unlikely to ever be
DebunkingThe US has no extradition treaty with China, none of the four defendants named in the February 2020 indictment were in custody, and officials acknowledged at the time there was little prospect any would appear in a US court. The attribution to Chinese military hackers is a formally charged US government position based on forensic investigation, but it has not been tested through an adversarial criminal trial the way the Jun Ying insider-trading case was.
Rebuttal
This is a limitation on how the evidence should be weighted, not a rebuttal of the attribution itself — DOJ's forensic case remains the official US position and is treated in this entry as strong but prosecutorial, not judicially adjudicated, evidence.
Analysts dispute whether indicting untriable foreign state hackers has any deterrent effect
DebunkingCommentators including a Brookings Institution fellow have argued that the broader US practice of indicting state-linked hackers who will never stand trial — a practice covering the Equifax case and others since 2014 — has not measurably reduced Chinese state-sponsored cybertheft, suggesting the indictment's function may be diplomatic or legal signaling rather than actual deterrence or restitution.
Rebuttal
This critiques the indictment's real-world effectiveness as a remedy, not the underlying facts of the breach or the DOJ's attribution.
FTC's advertised $125 settlement payout was walked back to a fraction of that amount
DebunkingStrongThe FTC initially told consumers they could choose a $125 cash payment instead of credit monitoring, but only $31 million was set aside for that option. After far more claimants than expected chose cash, the FTC said in July 2019 that payouts would be "nowhere near" $125 per person, and Senator Elizabeth Warren asked the agency's Inspector General to investigate the FTC's own public communications as misleading.
Rebuttal
This is a limitation on the settlement's consumer-facing adequacy, not a reason to doubt that the $700 million settlement itself occurred or that Equifax was found liable.
No confirmed evidence the stolen data was ever sold or used for identity theft, consistent with an espionage rather than financial-crime motive
DebunkingUnlike most large consumer data breaches, the Equifax data has not been confirmed to surface on dark-web marketplaces or generate a documented wave of identity theft. Commentary following the 2020 PLA indictment noted this is consistent with state-sponsored intelligence collection rather than financially motivated cybercrime — which also means the credit-monitoring remedy central to the 2019 settlement was arguably built for the wrong threat model.
Rebuttal
Absence of confirmed dark-web resale is not proof the data was never or will never be misused; it is the state of public evidence as of the settlement and indictment.
CEO Richard Smith retained an estimated $18-24 million in pension and stock despite the breach
NeutralSmith forfeited his 2017 bonus but was not subject to clawback on the bulk of his compensation, because Equifax's clawback policy at the time covered only accounting fraud, not losses from a security failure or settlement. This shows a structural incentive-and-accountability gap that predates the breach, distinguishing it from the personal insider-trading conduct that was separately charged and convicted.
Apache Struts Patch Failure Was Negligence in an Enterprise-Wide Process, Not Coordination
DebunkingThe Equifax breach exploited CVE-2017-5638, a critical Apache Struts vulnerability for which a patch had been available for two months before the breach. Internal communications revealed the patch was identified, communicated to IT teams, but not applied to the specific dispute-portal system due to process failures in Equifax's patch-management workflow. This is enterprise IT negligence — the failure of large organizations to consistently apply patches across complex legacy environments — not evidence of deliberate decision to leave vulnerabilities open.
Insider Trading Convictions Were Personal, Not Systematic Corporate Conspiracy
DebunkingFormer Equifax executive Jun Ying was convicted of insider trading for selling stock options after learning of the breach but before public disclosure. A second employee, Sudhakar Bonthu, pleaded guilty to similar charges. Both were individual actors taking personal advantage of material non-public information — not evidence of a boardroom-coordinated stock-manipulation scheme. Ying's prosecution and conviction demonstrate that securities enforcement identified and punished the individual misconduct, which is accountability operating as intended.
Evidence Cited by Believers8
CVE-2017-5638 patch available 8 March 2017 — breach began 13 May 2017
SupportingStrongThe Apache Struts vulnerability exploited in the Equifax breach had a publicly available patch 66 days before the breach began. US-CERT issued alerts the same day as the patch release. Equifax's security team was notified. The failure to apply the patch is documented in congressional testimony by CEO Richard Smith.
78-day undetected breach period
SupportingStrongFrom 13 May to 29 July 2017, attackers exfiltrated data for 78 days without detection. This duration is evidence of inadequate monitoring and detection capabilities relative to the sensitivity of the data Equifax held.
Executives sold $1.8M in stock between discovery and public disclosure
SupportingStrongCFO John Gamble, Joseph Loughran, and Rodolfo Ploder sold a combined $1.8 million in shares between 29 July 2017 (discovery) and 7 September 2017 (public disclosure). The company attributed the sales to pre-arranged trading plans.
Rebuttal
The company's claim that the sales were pre-arranged trading plans under 10b5-1 programmes was accepted as an explanation for most of the executives' trades. The DOJ pursued charges only against Jun Ying and Sudhakar Bonthu, not the CFO or the two presidents.
Jun Ying convicted of insider trading — sentenced to four months
SupportingStrongFormer Equifax CIO Jun Ying was charged by the DOJ with insider trading for selling approximately $950,000 in stock options in August 2017 after learning his company was the breach victim. He was convicted at trial in 2019 and sentenced to four months in prison and $117,117 in disgorgement.
$700M FTC and state AG settlement — largest data breach settlement at the time
SupportingStrongIn July 2019 Equifax settled with the FTC, CFPB, and all 50 state attorneys general for $700 million, including up to $425 million in consumer restitution. It was the largest data breach settlement in US history at the time of announcement.
CEO, CIO, and CSO all resigned 26 September 2017
SupportingRichard Smith (CEO), David Webb (CIO), and Susan Mauldin (CSO) all departed on 26 September 2017. The simultaneous resignation of the top security and technical leadership was widely interpreted as accountability for the breach and the response.
GAO-18-559 identified four systemic causes, not just an unpatched vulnerability
SupportingStrongThe Government Accountability Office's August 2018 report (GAO-18-559) found the breach resulted from documented weaknesses across four areas: identification of at-risk systems, detection of the intrusion, database segmentation, and data governance — an independent congressional audit corroborating that the failure was architectural, not a single missed patch.
House Oversight report found an expired security certificate blinded intrusion detection for 19 months
SupportingStrongThe House Oversight Committee's December 2018 report found Equifax's intrusion-detection system could not inspect encrypted traffic for 19 months because a required digital certificate had expired and was not renewed, and that the Chief Security Officer reported to the legal department rather than the CIO — a documented structural accountability gap beyond the single missed-scan explanation given in 2017 congressional testimony.
Counter-Evidence6
The four indicted PLA officers were never tried, and are unlikely to ever be
DebunkingThe US has no extradition treaty with China, none of the four defendants named in the February 2020 indictment were in custody, and officials acknowledged at the time there was little prospect any would appear in a US court. The attribution to Chinese military hackers is a formally charged US government position based on forensic investigation, but it has not been tested through an adversarial criminal trial the way the Jun Ying insider-trading case was.
Rebuttal
This is a limitation on how the evidence should be weighted, not a rebuttal of the attribution itself — DOJ's forensic case remains the official US position and is treated in this entry as strong but prosecutorial, not judicially adjudicated, evidence.
Analysts dispute whether indicting untriable foreign state hackers has any deterrent effect
DebunkingCommentators including a Brookings Institution fellow have argued that the broader US practice of indicting state-linked hackers who will never stand trial — a practice covering the Equifax case and others since 2014 — has not measurably reduced Chinese state-sponsored cybertheft, suggesting the indictment's function may be diplomatic or legal signaling rather than actual deterrence or restitution.
Rebuttal
This critiques the indictment's real-world effectiveness as a remedy, not the underlying facts of the breach or the DOJ's attribution.
FTC's advertised $125 settlement payout was walked back to a fraction of that amount
DebunkingStrongThe FTC initially told consumers they could choose a $125 cash payment instead of credit monitoring, but only $31 million was set aside for that option. After far more claimants than expected chose cash, the FTC said in July 2019 that payouts would be "nowhere near" $125 per person, and Senator Elizabeth Warren asked the agency's Inspector General to investigate the FTC's own public communications as misleading.
Rebuttal
This is a limitation on the settlement's consumer-facing adequacy, not a reason to doubt that the $700 million settlement itself occurred or that Equifax was found liable.
No confirmed evidence the stolen data was ever sold or used for identity theft, consistent with an espionage rather than financial-crime motive
DebunkingUnlike most large consumer data breaches, the Equifax data has not been confirmed to surface on dark-web marketplaces or generate a documented wave of identity theft. Commentary following the 2020 PLA indictment noted this is consistent with state-sponsored intelligence collection rather than financially motivated cybercrime — which also means the credit-monitoring remedy central to the 2019 settlement was arguably built for the wrong threat model.
Rebuttal
Absence of confirmed dark-web resale is not proof the data was never or will never be misused; it is the state of public evidence as of the settlement and indictment.
Apache Struts Patch Failure Was Negligence in an Enterprise-Wide Process, Not Coordination
DebunkingThe Equifax breach exploited CVE-2017-5638, a critical Apache Struts vulnerability for which a patch had been available for two months before the breach. Internal communications revealed the patch was identified, communicated to IT teams, but not applied to the specific dispute-portal system due to process failures in Equifax's patch-management workflow. This is enterprise IT negligence — the failure of large organizations to consistently apply patches across complex legacy environments — not evidence of deliberate decision to leave vulnerabilities open.
Insider Trading Convictions Were Personal, Not Systematic Corporate Conspiracy
DebunkingFormer Equifax executive Jun Ying was convicted of insider trading for selling stock options after learning of the breach but before public disclosure. A second employee, Sudhakar Bonthu, pleaded guilty to similar charges. Both were individual actors taking personal advantage of material non-public information — not evidence of a boardroom-coordinated stock-manipulation scheme. Ying's prosecution and conviction demonstrate that securities enforcement identified and punished the individual misconduct, which is accountability operating as intended.
Neutral / Ambiguous3
Consumer restitution payouts far below advertised amounts
NeutralThe FTC's initial advertising of up to $125 per consumer was criticised when the volume of claims made clear the actual per-person payout would be far smaller. The FTC updated guidance to recommend consumers take credit monitoring services instead of cash payouts.
Rebuttal
The settlement cap was $425M for consumer restitution. With 147.9M potential claimants and high claim volume, per-consumer cash payouts were inevitably small. The FTC's communications around the settlement were criticised as misleading by consumer advocates.
Congressional testimony attributed patch failure to a single individual
NeutralCEO Richard Smith testified before Congress that the failure to apply the patch resulted from a breakdown in Equifax's internal scanning process — one individual had failed to run the scan that would have identified the vulnerable system. Critics argued this deflected institutional accountability onto a single employee.
Rebuttal
Attributing a systemic failure in patch management to a single individual's error was widely criticised by security professionals as a deflection from institutional governance failures. Patch management processes should not depend on a single point of failure.
CEO Richard Smith retained an estimated $18-24 million in pension and stock despite the breach
NeutralSmith forfeited his 2017 bonus but was not subject to clawback on the bulk of his compensation, because Equifax's clawback policy at the time covered only accounting fraud, not losses from a security failure or settlement. This shows a structural incentive-and-accountability gap that predates the breach, distinguishing it from the personal insider-trading conduct that was separately charged and convicted.
Timeline
Apache Struts CVE-2017-5638 patch published
NIST publishes CVE-2017-5638 in the National Vulnerability Database. US-CERT issues an alert. The patch for the remote code execution vulnerability is publicly available. Equifax's security team is notified. The patch is not applied to the ACIS dispute portal system.
Source →Breach begins — attackers exploit unpatched Struts vulnerability
Attackers begin exploiting the unpatched CVE-2017-5638 in Equifax's ACIS consumer dispute portal, 66 days after the patch was available. Exfiltration of 147.9 million Americans' PII — Social Security numbers, dates of birth, addresses — begins.
Breach discovered internally; executives begin stock sales
Equifax's security team discovers the intrusion after 78 days of undetected access. CFO John Gamble and two other executives sell a combined $1.8M in shares in the days following discovery, before public disclosure. Jun Ying, separately, sells options worth approximately $950,000.
Public disclosure; CEO and senior leadership resign 26 Sep 2017
Equifax discloses the breach publicly on 7 September 2017, 40 days after discovery. CEO Richard Smith, CIO David Webb, and CSO Susan Mauldin all resign on 26 September 2017. Congressional hearings begin in early October. Smith testifies the patch failure was the result of a single employee failing to run a required scan.
Source →
Verdict
CVE-2017-5638 patch was available 8 March 2017. Breach began 13 May 2017. Discovered 29 July 2017. Disclosed 7 September 2017. CFO and three executives sold $1.8M in stock between discovery and disclosure. Jun Ying convicted of insider trading 2019. $700M FTC + state AG settlement July 2019. CEO Richard Smith, CIO David Webb, and CSO Susan Mauldin all resigned 26 September 2017.
Frequently Asked Questions
Why was the Equifax patch never applied if it was available months earlier?
CEO Richard Smith testified to Congress that the failure resulted from a breakdown in Equifax's internal patch scanning process — a single employee had failed to run the scan that would have identified the vulnerable system. Security professionals widely criticised this explanation as deflecting systemic governance failure onto an individual, arguing that a patch management process with a single point of failure was itself the institutional problem.
Were the executive stock sales before disclosure illegal?
The DOJ charged former CIO Jun Ying and manager Sudhakar Bonthu with insider trading. Both were convicted or pleaded guilty. The CFO's and two presidents' sales were attributed to pre-arranged 10b5-1 trading plans and were not prosecuted. Whether the trading-plan defence was fully adequate remains a subject of criticism from securities law scholars.
How much did affected consumers actually receive from the settlement?
The FTC initially advertised up to $125 in cash per claimant. Due to the volume of claims — far exceeding the $31 million cash fund — actual cash payouts were a small fraction of that amount. The FTC updated guidance to recommend free credit monitoring services instead. Consumer advocates criticised the settlement terms and the FTC's communications as misleading.
Were the Chinese military officers charged with the Equifax hack ever arrested or put on trial?
Sources
Show 16 more sources
Further Reading
- bookCountdown to Zero Day: Stuxnet and the Launch of the World's First Digital Weapon — Kim Zetter (2014)
- paperSenate Banking Committee hearing: Equifax data breach — US Senate Banking Committee (2017)
- paperData Protection: Actions Taken by Equifax and Federal Agencies in Response to the 2017 Breach (GAO-18-559) — US Government Accountability Office (2018)
- paperThe Equifax Data Breach: Majority Staff Report, 115th Congress — US House Committee on Oversight and Government Reform (2018)
- articleFTC Equifax data breach settlement — official case page — Federal Trade Commission (2019)
- articleThe enormous Equifax hack looks a lot more bizarre now — Slate (2020)