Equifax disclosed in September 2017 that attackers had exploited an unpatched Apache Struts vulnerability (CVE-2017-5638) in its ACIS dispute-portal database, ultimately exposing the personal data of roughly 147 million Americans in what became one of the most consequential consumer-data breaches in U.S. history. According to the FTC, Equifax was alerted to the critical flaw in March 2017 and ordered a 48-hour patch, but the directive was never executed; the company did not discover the unpatched system until July 2017, by which point multiple hackers had used administrative credentials stored in plain text to roam the network for months. Stolen data included 147 million names and dates of birth, 145.5 million Social Security numbers, and 209,000 payment-card numbers. On July 22, 2019, Equifax reached a global settlement with the FTC, the CFPB and 48 states, the District of Columbia and Puerto Rico, agreeing to pay at least $575 million and potentially up to $700 million, then the largest data-breach settlement in U.S. history. The package included $300 million (extendable by $125 million) for consumer restitution and credit monitoring, $175 million to the states, and $100 million to the CFPB, along with mandatory comprehensive security-program reforms and biennial third-party assessments. Aggregate breach costs across all litigation have since been reported at roughly $1.38 billion.
Blog
Insights on AI security and development
Learn how to protect your code, understand AI risks, and build secure workflows with expert insights.

