Case file · EQUIFAX 2017

What caused the Equifax breach? An unpatched website and an expired certificate

Published 2026-09-26 · 4 min read

For at least 10 months before anyone noticed, a security device at Equifax that was supposed to inspect encrypted web traffic had been effectively blind, because a digital certificate it relied on had expired.[1] This case file walks through how an unpatched flaw in a consumer dispute website led to the exposure of personal data on about 147 million people, how it was finally spotted, what it cost, and the two plain habits that would have stopped it.[4]

What happened

On March 7, 2017, a serious flaw was publicly disclosed in Apache Struts, a widely used building block for web applications, and a fix was released.[2] The government's computer emergency team flagged it to Equifax on March 8, and on March 9 Equifax's security staff emailed an internal notice telling system owners to apply the update within 48 hours.[2] One of the systems running the vulnerable software was Equifax's online dispute portal, the site consumers use to challenge errors on their credit reports. It was never patched.[5]

A scan run on March 15 was supposed to find any remaining vulnerable systems. It found none.[5] Meanwhile, outsiders had already begun probing Equifax systems for the flaw as early as March 10.[1] On May 13, 2017, attackers got into the dispute portal and stayed for about 76 days.[2]

During that stretch they found stored usernames and passwords, used them to reach dozens of databases that had nothing to do with disputes, and ran roughly 9,000 queries.[1][2] On July 29, Equifax renewed an expired certificate on its traffic-inspection equipment. With the device able to see again, staff immediately noticed suspicious traffic tied to the dispute portal. They blocked it that day and took the portal offline on July 30.[2][5] The public learned about the breach on September 7, 2017.[5]

How they got in

The front door was the known Struts flaw. Because the dispute portal was still running the old version months after the fix came out, the attackers could send it specially crafted requests that made the server run commands on their behalf.[3] That gave them a foothold inside Equifax's network.

Three weaknesses turned that foothold into a disaster. First, the network was not divided into walled-off sections, so a break-in at one public website could reach 48 unrelated databases.[2] Second, credentials were stored unencrypted where the intruders could read them, which let them log in to more systems.[1] Third, nothing limited how many queries could be run, so thousands of requests pulling out personal data went unchallenged.[1]

According to the Justice Department, the intruders also covered their tracks: they routed traffic through about 34 servers in nearly 20 countries, used encrypted channels, and deleted log files.[3] Encrypted traffic is exactly what the inspection device was meant to examine, and with its certificate expired, it was not examining anything. A congressional investigation found Equifax had let more than 300 security certificates lapse, including 79 used to monitor business-critical domains.[2]

How it was caught and what it cost

Nobody caught the intruders through a clever investigation. Detection came as a side effect of routine maintenance: renewing the lapsed certificate switched the inspection back on, and the suspicious traffic was visible almost at once.[2] Equifax then brought in an outside incident-response firm on August 2.[5]

Stolen data included names, Social Security numbers, birth dates, addresses and some driver's license numbers, plus about 209,000 credit card numbers.[1] Equifax's chief executive stepped down before testifying to Congress in October 2017 that the breach came from both human error and technology failures.[5] A House committee report later called the breach "entirely preventable."[2]

In July 2019, Equifax agreed to a settlement with the Federal Trade Commission, the Consumer Financial Protection Bureau 48 states, Washington, D.C., and Puerto Rico worth at least $575 million and up to $700 million, including up to $425 million for affected consumers, $175 million to the states and a $100 million civil penalty to the CFPB.[4]

In February 2020, the Justice Department charged four members of China's People's Liberation Army with computer fraud, economic espionage and wire fraud. DOJ attributed the intrusion to that unit of the Chinese military. The four were charged only; none has been tried.[3]

The missing control

The missing control: timely patching, backed by verified monitoring that proves your security tools are actually working.

Equifax did send the patch notice. What it lacked was follow-through: no one confirmed the dispute portal had actually been updated, and the FTC said the company did not check that its own patch order was carried out.[4] A patch applied in March would have closed the door two months before the attackers walked through it.

The second half matters just as much. A monitoring tool that silently stops working is worse than none, because it creates false confidence. A simple check that the inspection device was seeing traffic, or an alert when its certificate was about to expire, would likely have cut the 76 days down to hours or days.

What to do in your business

Watch the case
Episode drops 2026-09-30
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More case files

Facts are drawn from court records, government reports and reputable reporting, listed below. People are named only where they were convicted or spoke publicly in an official role.

Sources
  1. U.S. Government Accountability Office: Data Protection: Actions Taken by Equifax and Federal Agencies in Response to the 2017 Breach (GAO-18-559)
  2. House Committee on Oversight and Government Reform: The Equifax Data Breach (Majority Staff Report, December 2018)
  3. U.S. Department of Justice: Chinese Military Personnel Charged with Computer Fraud, Economic Espionage and Wire Fraud for Hacking into Credit Reporting Agency Equifax
  4. Federal Trade Commission: Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach
  5. U.S. House Energy and Commerce Committee: Prepared Testimony of Richard F. Smith, October 3, 2017