01Summary
The breach began in May 2017 when threat actors gained initial access to Equifax's network by exploiting a known vulnerability (CVE-2017-5638) in the Apache Struts framework. The attackers maintained persistence and operated undetected for approximately 76 days, systematically exfiltrating vast amounts of consumer data. The stolen data included names, dates of birth, Social Security numbers (SSNs), driver's license numbers, and credit card details belonging to millions of individuals. The breach was publicly disclosed in September 2017, leading to intense regulatory scrutiny, massive class-action lawsuits, and a multi-million dollar settlement with the Federal Trade Commission (FTC).
02Background
Equifax is one of the three major credit reporting agencies in the United States, holding highly sensitive financial and personal data. The industry relies heavily on the integrity of these data repositories, making them prime targets for state-sponsored espionage and financial crime. The vulnerability exploited was a widely known flaw in the Struts framework, which had been available for some time.
03Key revelations
- 01The theft of SSNs and PII for 147 million Americans, representing a massive identity theft risk.
- 02The vulnerability exploited (CVE-2017-5638) was a known, unpatched flaw in a widely used framework.
- 03The breach exposed systemic failures in Equifax's internal security patching and monitoring processes.
04Technical analysis
The initial access was achieved via a Remote Code Execution (RCE) vulnerability in the Apache Struts framework. Once inside, the attackers moved laterally through the network, escalating privileges and deploying custom malware to locate and compress the target data. The exfiltration was conducted over a period of weeks, suggesting a methodical, intelligence-gathering operation rather than a quick smash-and-grab.
- Attack vector
- Exploitation of a vulnerability in the Apache Struts web framework (CVE-2017-5638).
- Attack method
- Remote Code Execution (RCE) leading to data exfiltration and lateral movement.
- Initial access
- Exploitation of public-facing web application vulnerability
- Lateral movement
- Internal network traversal and privilege escalation
- Persistence
- Installation of backdoors or compromised credentials
- Exfiltration
- Bulk transfer of compressed data over the network
- Tool / malware
- Custom malware/scripts (specific names not publicly confirmed)
- Malware type
- Stealer/Backdoor
Vulnerabilities exploited
- CVE-2017-5638
MITRE ATT&CK techniques
- T1190
- T1078
05Threat actor
Attributed to state-sponsored actors, this group is characterized by sophisticated, long-term espionage operations. Their focus is on acquiring high-value, aggregated PII, suggesting a mandate from a national intelligence service rather than purely financial gain.
Aliases
- APT3
- China State Actor
APT designations
- APT3
MITRE groups
- T1190
- T1078
Attribution sources
- The Washington Post
- The New York Times
- Mandiant
06Victims and impact
Additional victims
- US Consumers
Countries affected
- United States
07Data exposed
Data types
- Social Security Numbers
- Names
- Dates of Birth
- Credit Card Numbers
- Driver's License Numbers
- PII
Notable documents
- Internal network logs (compromised)
- Consumer PII databases
08Financial damage
Maximum settlement amount agreed to with the FTC, not the total cost of damages.
09Timeline
- 2017-05-13Initial unauthorized access to Equifax systems via Struts vulnerability.
- 2017-07-29Equifax discovered the breach and began internal investigation.
- 2017-09-07Public disclosure of the breach to the media and consumers.
- 2019-07-29FTC settlement agreement finalized, imposing fines and mandatory security changes.
10Key figures
- Equifax Inc.Victim Organization · Equifax Inc.Settled with FTC and paid significant fines.
11On the record
The breach demonstrated the negligence of major credit bureaus in protecting sensitive consumer data.
12Reaction and fallout
Public reaction
The public reaction was characterized by widespread panic regarding identity theft and the perceived failure of major financial institutions. Consumer advocacy groups heavily criticized the lack of security measures.
Political impact
The breach led to increased regulatory scrutiny of the entire credit reporting industry, prompting calls for federal legislation to mandate stronger data protection standards and breach notification protocols.
Geopolitical consequences
The incident was widely cited as evidence of sophisticated, state-sponsored cyber espionage targeting critical US infrastructure and personal data, raising concerns about national economic security.
13Legal
Equifax agreed to a settlement with the FTC and state attorneys general, which included a mandatory security overhaul and a substantial monetary penalty. Multiple class-action lawsuits were also filed and settled.
Prosecutions
- Equifax Inc.Settlement reached
- Charge
- Failure to protect consumer data; negligence
- Jurisdiction
- Federal Trade Commission (FTC)
- Sentence
- Up to $700 million in fines and required security improvements.
Civil lawsuits
- Class-action lawsuits filed by affected consumers
14Aftermath
Policy changes
- Increased focus on mandatory, industry-wide security patching and vulnerability management for critical infrastructure.
Regulatory changes
- Heightened regulatory oversight of the credit reporting industry by federal bodies.
Security improvements
- Mandatory multi-factor authentication (MFA) for sensitive data access.
- Improved network segmentation to limit lateral movement during a breach.
15Significance and legacy
Significance
This breach is historically significant because it demonstrated the immense value of aggregated PII and the critical vulnerability of legacy enterprise systems to state-sponsored actors. It set a precedent for the scale of financial penalties and regulatory action following a major data breach.
Legacy
The incident accelerated the global conversation around data sovereignty, mandatory security standards (like GDPR), and the necessity of continuous, proactive vulnerability management in the financial sector. It remains a benchmark case study in corporate cybersecurity failure.
16Disclosure and media
- Authentication
- Publicly disclosed forensic reports and regulatory filings
Media partners
- The New York Times
- The Washington Post
- Reuters
Publishing organisations
- The New York Times
- The Washington Post
17Field notes
- 01The vulnerability exploited, CVE-2017-5638, was a flaw in the Apache Struts framework, a widely used component in enterprise web applications.
- 02The sheer volume of data stolen—SSNs, credit cards, and driver's licenses—made it a prime target for identity theft rings globally.
18Resolution
The company paid the settlement and was required to implement comprehensive security upgrades and governance changes over several years.
19Sources
Official documents
- FTC Settlement Agreement (2019)
References
- [1]Federal Trade Commission (FTC) Press Releases
- [2]The New York Times Investigative Reports
- [3]Mandiant Threat Intelligence Reports









