EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/equifax-breach-2017
238/430

File EL-0193CriticalResolvedData Breach / Consumer PII Exfiltration

Equifax Data Breach

Also filed as Equifax Security Breach · Equifax Data Theft

The Equifax breach was a massive data exfiltration event where hackers stole the personal identifying information (PII) of nearly 147 million Americans. The attack exploited a critical vulnerability in the Apache Struts web framework, allowing unauthorized access to the company's core systems. The incident highlighted severe deficiencies in corporate cybersecurity protocols and data protection.

  • #equifax
  • #data-breach
  • #ssn-theft
  • #apache-struts
  • #pii
  • #cybersecurity
Notoriety9/10
Event
13 May 2017
Disclosed
7 Sept 2017
Target
Equifax Inc.
Actor
China (PLA Unit 61398)
Scale
147.0M people
Status
Resolved

01Summary

The breach began in May 2017 when threat actors gained initial access to Equifax's network by exploiting a known vulnerability (CVE-2017-5638) in the Apache Struts framework. The attackers maintained persistence and operated undetected for approximately 76 days, systematically exfiltrating vast amounts of consumer data. The stolen data included names, dates of birth, Social Security numbers (SSNs), driver's license numbers, and credit card details belonging to millions of individuals. The breach was publicly disclosed in September 2017, leading to intense regulatory scrutiny, massive class-action lawsuits, and a multi-million dollar settlement with the Federal Trade Commission (FTC).

02Background

Equifax is one of the three major credit reporting agencies in the United States, holding highly sensitive financial and personal data. The industry relies heavily on the integrity of these data repositories, making them prime targets for state-sponsored espionage and financial crime. The vulnerability exploited was a widely known flaw in the Struts framework, which had been available for some time.

03Key revelations

  1. 01The theft of SSNs and PII for 147 million Americans, representing a massive identity theft risk.
  2. 02The vulnerability exploited (CVE-2017-5638) was a known, unpatched flaw in a widely used framework.
  3. 03The breach exposed systemic failures in Equifax's internal security patching and monitoring processes.

04Technical analysis

The initial access was achieved via a Remote Code Execution (RCE) vulnerability in the Apache Struts framework. Once inside, the attackers moved laterally through the network, escalating privileges and deploying custom malware to locate and compress the target data. The exfiltration was conducted over a period of weeks, suggesting a methodical, intelligence-gathering operation rather than a quick smash-and-grab.

Attack vector
Exploitation of a vulnerability in the Apache Struts web framework (CVE-2017-5638).
Attack method
Remote Code Execution (RCE) leading to data exfiltration and lateral movement.
Initial access
Exploitation of public-facing web application vulnerability
Lateral movement
Internal network traversal and privilege escalation
Persistence
Installation of backdoors or compromised credentials
Exfiltration
Bulk transfer of compressed data over the network
Tool / malware
Custom malware/scripts (specific names not publicly confirmed)
Malware type
Stealer/Backdoor

Vulnerabilities exploited

  • CVE-2017-5638

MITRE ATT&CK techniques

  • T1190
  • T1078

05Threat actor

Attributed to state-sponsored actors, this group is characterized by sophisticated, long-term espionage operations. Their focus is on acquiring high-value, aggregated PII, suggesting a mandate from a national intelligence service rather than purely financial gain.

Aliases

  • APT3
  • China State Actor

APT designations

  • APT3

MITRE groups

  • T1190
  • T1078

Attribution sources

  • The Washington Post
  • The New York Times
  • Mandiant

06Victims and impact

Additional victims

  • US Consumers

Countries affected

  • United States

07Data exposed

Data types

  • Social Security Numbers
  • Names
  • Dates of Birth
  • Credit Card Numbers
  • Driver's License Numbers
  • PII

Notable documents

  • Internal network logs (compromised)
  • Consumer PII databases

08Financial damage

Maximum settlement amount agreed to with the FTC, not the total cost of damages.

09Timeline

  1. 2017-05-13Initial unauthorized access to Equifax systems via Struts vulnerability.
  2. 2017-07-29Equifax discovered the breach and began internal investigation.
  3. 2017-09-07Public disclosure of the breach to the media and consumers.
  4. 2019-07-29FTC settlement agreement finalized, imposing fines and mandatory security changes.

10Key figures

  • Equifax Inc.Victim Organization · Equifax Inc.Settled with FTC and paid significant fines.

11On the record

The breach demonstrated the negligence of major credit bureaus in protecting sensitive consumer data.

Source Content, General assessment of the incident's impact.

12Reaction and fallout

Public reaction

The public reaction was characterized by widespread panic regarding identity theft and the perceived failure of major financial institutions. Consumer advocacy groups heavily criticized the lack of security measures.

Political impact

The breach led to increased regulatory scrutiny of the entire credit reporting industry, prompting calls for federal legislation to mandate stronger data protection standards and breach notification protocols.

Geopolitical consequences

The incident was widely cited as evidence of sophisticated, state-sponsored cyber espionage targeting critical US infrastructure and personal data, raising concerns about national economic security.

13Legal

Equifax agreed to a settlement with the FTC and state attorneys general, which included a mandatory security overhaul and a substantial monetary penalty. Multiple class-action lawsuits were also filed and settled.

Prosecutions

  • Equifax Inc.Settlement reached
    Charge
    Failure to protect consumer data; negligence
    Jurisdiction
    Federal Trade Commission (FTC)
    Sentence
    Up to $700 million in fines and required security improvements.

Civil lawsuits

  • Class-action lawsuits filed by affected consumers

14Aftermath

Policy changes

  • Increased focus on mandatory, industry-wide security patching and vulnerability management for critical infrastructure.

Regulatory changes

  • Heightened regulatory oversight of the credit reporting industry by federal bodies.

Security improvements

  • Mandatory multi-factor authentication (MFA) for sensitive data access.
  • Improved network segmentation to limit lateral movement during a breach.

15Significance and legacy

Significance

This breach is historically significant because it demonstrated the immense value of aggregated PII and the critical vulnerability of legacy enterprise systems to state-sponsored actors. It set a precedent for the scale of financial penalties and regulatory action following a major data breach.

Legacy

The incident accelerated the global conversation around data sovereignty, mandatory security standards (like GDPR), and the necessity of continuous, proactive vulnerability management in the financial sector. It remains a benchmark case study in corporate cybersecurity failure.

16Disclosure and media

Authentication
Publicly disclosed forensic reports and regulatory filings

Media partners

  • The New York Times
  • The Washington Post
  • Reuters

Publishing organisations

  • The New York Times
  • The Washington Post

17Field notes

  1. 01The vulnerability exploited, CVE-2017-5638, was a flaw in the Apache Struts framework, a widely used component in enterprise web applications.
  2. 02The sheer volume of data stolen—SSNs, credit cards, and driver's licenses—made it a prime target for identity theft rings globally.

18Resolution

The company paid the settlement and was required to implement comprehensive security upgrades and governance changes over several years.

19Sources

Official documents

  • FTC Settlement Agreement (2019)

References

  1. [1]Federal Trade Commission (FTC) Press Releases
  2. [2]The New York Times Investigative Reports
  3. [3]Mandiant Threat Intelligence Reports
Fact sheetEL-0193

Dates

Event
13 May 2017
Started
13 May 2017
Ended
29 Jul 2017
Duration
77 days
Discovered
29 Jul 2017
Disclosed
7 Sept 2017
Resolved
29 Jul 2020
Ongoing
No

Target

Organisation
Equifax Inc.
Type
Corporation
Sector
Credit Reporting/Financial Services
Country
United States

Actor

Name
China (PLA Unit 61398)
Type
Nation-State Actor
Nationality
China
Nation-state
China
Affiliation
People's Liberation Army (PLA)
Motivation
Espionage and theft of sensitive personal and financial data for state benefit.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

People
147,000,000
Records
147,000,000
Volume
Estimated multiple terabytes of data
Sensitivity
Top Secret
Published
No
Sold (dark web)
Yes

Money

Damage
$700,000,000

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.