The Equifax breach, start to finish: a missed patch, an expired certificate and 147 million people
For 76 days in 2017, intruders pulled personal data out of Equifax, one of the 3 big U.S. credit bureaus, while the device meant to spot them sat blind behind an expired certificate.[1][3] By the time the count settled, about 147 million people had been exposed.[4] This long read follows the whole heist in order: the patch alert that went astray, the break-in, the blind spot, the weeks of silence, the bill, and the control that would have stopped it.
The patch alert that never reached the right person
Equifax keeps credit files on most American adults, and in 2017 it ran a public website where people could dispute errors in their reports. That online dispute portal was built with Apache Struts, a widely used framework for building web applications.[1][6] On March 8, 2017, the U.S. Computer Emergency Readiness Team, the federal government's cyber warning center, publicly flagged a serious flaw in Struts, tracked as CVE-2017-5638.[1][9] Just 2 days later, on March 10, unidentified outsiders found that Equifax's dispute portal still had the flaw.[1]
Equifax's security team did react. An internal alert went out to roughly 430 people and several distribution lists, calling for the fix to be applied within 48 hours, as company policy required.[3] But the list of recipients was out of date, so the notice never reached the administrators who actually looked after the dispute portal.[1] A network scan run afterward to find vulnerable systems did not detect the flaw on the portal either.[1]
The Federal Trade Commission later summed up the gap in one line of its complaint: Equifax ordered the patch but did not follow up to make sure the responsible employees carried it out.[4] The portal stayed unpatched through the spring and into July.[4]
None of this was exotic. A public warning, a ready fix and a policy with a deadline were all in place. What was missing was a named person who had to confirm the work was done, and a check that would notice if it was not. An email to a stale list feels like action, but it is only a hope that someone else will act.
How attackers got from one website to 48 databases
On May 13, 2017, the attackers used the unpatched flaw to get inside the dispute portal.[1][3] The portal was connected to only 3 databases. Inside that environment, though, they found usernames and passwords stored without encryption. Those credentials let them reach an additional 48 databases that had nothing to do with disputes.[1] The FTC later alleged that Equifax had kept network credentials, passwords and Social Security numbers in plain text.[4]
Government investigators counted about 9,000 queries run against Equifax's systems during the intrusion.[1] House investigators found that 265 of them returned personal information.[3] That was enough. The data taken included names, birth dates and Social Security numbers for more than 145 million people, and payment card numbers for about 209,000 consumers.[1][4]
The intruders worked to stay out of sight. According to the Justice Department, they sent their traffic through about 34 servers in nearly 20 countries to hide where they were, and they deleted compressed files and wiped log files every day to erase traces of what they had done.[6] The stolen data left over encrypted connections, the same kind that protect ordinary web browsing, so it blended in with normal traffic.[1]
The expired certificate that blinded Equifax
Equifax did own equipment designed to look inside encrypted traffic and flag anything suspicious. To do that job, the device needed a valid digital certificate, a small file that works like an ID card for encrypted connections. Its certificate had lapsed. The Government Accountability Office said it had expired about 10 months before the breach began, and House investigators dated the lapse to January 31, 2016.[1][3] With the certificate expired, the device was not inspecting the encrypted traffic at all.
The House Oversight Committee found the problem was not a one-off. Equifax had allowed more than 300 security certificates to expire, including 79 used to monitor business-critical domains.[2] Inside a company that held data on roughly half the country, the tools existed but nobody was tracking whether they still worked.
On the evening of July 29, 2017, staff finally renewed the certificate. Almost at once, the security team spotted a suspicious request from an internet address in China.[3] The next day, July 30, Equifax took the dispute portal offline.[1] By then the attackers had been inside for about 76 days.[1][3] The chief executive was told on July 31, and an outside forensics firm was brought in on August 2.[3]
Five weeks of silence, a stock sale and a shaky help site
The public would not hear about the breach until September 7, 2017.[1] In between, one insider acted on what he knew. Jun Ying was the chief information officer of Equifax U.S. Information Solutions, one of the company's business units. On Friday, August 25, he texted a co-worker that the breach they were working on sounded bad and that Equifax might be the one breached.[5]
The following Monday, August 28, Ying searched online for how Experian's 2015 data breach had affected that company's stock price. Later that morning he exercised all of his stock options, received 6,815 Equifax shares, and sold them for more than $950,000.[5] When the breach was announced, Equifax's stock fell. By selling first, prosecutors said, he had avoided a loss of more than $117,000.[5]
The announcement itself went badly. Equifax first put the number of affected consumers at 143 million, a figure that would later grow.[3] The House found the company unprepared to identify, alert and support the people involved, and its breach website and call centers were overwhelmed.[2] Equifax had set up its help site on a separate, look-alike web address. A software engineer built an imitation with the words of the name swapped around to show how easy that was to copy, and Equifax's own Twitter account then pointed people to the imitation on at least 3 occasions before the posts were taken down.[7]
On September 26, 2017, the chief executive retired.[3] In congressional testimony that October, he told lawmakers that an individual had failed to make sure the patch notice reached the right person, and that the company's scanning software had not found the hole either.[8] He also said Equifax had made security investments approaching a quarter of a billion dollars.[8]
Settlements, a prison term and an indictment
Ying was the first person held criminally responsible. He pleaded guilty to insider trading on March 7, 2019. On June 27, 2019, a federal judge in Atlanta sentenced him to 4 months in prison and 1 year of supervised release, and ordered him to pay $117,117.61 in restitution and a $55,000 fine.[5]
In December 2018, after a 14-month investigation, the House Oversight Committee's majority staff concluded the breach was entirely preventable.[2] On July 22, 2019, Equifax agreed to a global settlement with the FTC, the Consumer Financial Protection Bureau and the states. It would pay at least $575 million and potentially up to $700 million. The deal included $300 million for credit monitoring and compensation for consumers, which could grow by up to $125 million, plus $175 million to 48 states, the District of Columbia and Puerto Rico, and $100 million in civil penalties to the consumer bureau.[4] The order also required Equifax's board to certify each year that the company was complying.[4]
The last piece came on February 10, 2020. The Justice Department charged four members of China's People's Liberation Army, from a unit called the 54th Research Institute, with hacking Equifax. The indictment lists 9 counts, including conspiracy to commit computer fraud, economic espionage and wire fraud.[6] The charges are accusations, not convictions, and the case has not gone to trial.
Walking the failures backwards
Read the story in reverse and every failure was ordinary. The data left unseen because a monitoring device had an expired certificate and nobody was tracking renewal dates.[2][3] The intruders roamed 48 extra databases because working passwords sat unencrypted where they could be found.[1] And they got in at all because a patch order went to an outdated list, a scan missed the target, and nobody had to prove the fix was in.[1][4]
Any one of those, fixed, would have stopped the heist or cut it short. The two that mattered most were simple: an owner for every patch who has to confirm it was applied, and monitoring that someone regularly tests to make sure it is actually watching.
Timeline
| Date | What happened |
|---|---|
| Jan 31, 2016 | Certificate on the traffic inspection device expires, per House investigators.[3] |
| Mar 8, 2017 | Federal cyber team publicly flags the Apache Struts flaw.[1] |
| Mar 10, 2017 | Outsiders find the flaw on Equifax's dispute portal.[1] |
| May 13, 2017 | Attackers break into the dispute portal.[1] |
| Jul 29, 2017 | Certificate renewed; suspicious traffic spotted.[3] |
| Jul 30, 2017 | Dispute portal taken offline.[1] |
| Aug 28, 2017 | Business unit CIO sells 6,815 shares before any announcement.[5] |
| Sep 7, 2017 | Equifax announces the breach.[1] |
| Sep 26, 2017 | Chief executive retires.[3] |
| Dec 10, 2018 | House Oversight report calls the breach entirely preventable.[2] |
| Jul 22, 2019 | Settlement of at least $575 million, up to $700 million.[4] |
| Feb 10, 2020 | Justice Department charges 4 Chinese military members.[6] |
The missing control
The missing control: verified patching with a named owner, and monitoring that is regularly tested to prove it still works. A confirmed patch would have kept the attackers out in March; a working inspection device would have caught them in May instead of late July.[1][3]
- Keep a list of everything facing the internet. Write down your website, online booking or payment pages, remote access tools and any server customers or staff reach from outside, with the person responsible for each.
- Give every patch an owner and a deadline. When a serious update comes out, assign it to a named person, not a group email, and set a date it must be done by.
- Ask for proof, not promises. Have the owner or your IT provider confirm the update is installed, with a version number or screenshot, and recheck the system a week later.
- Put expiry dates on a calendar. Track renewal dates for website certificates, domain names, security subscriptions and antivirus licenses, with reminders 30 days ahead.
- Test that your alarms still ring. A few times a year, ask your IT provider to show you a recent alert from your firewall or security software, and never leave passwords sitting in plain files or spreadsheets.
What it means now
Equifax was not short of money or tools. It had a patch policy, a scanner and a device built to watch its traffic. Each one failed quietly, and no one noticed because nobody was checking that the checks worked.
A small business will never hold 147 million records, but the shape of the risk is the same. An update that nobody confirmed and a security tool that expired last year look fine on paper right up until the day they matter. Put a name next to each one and look at them on a schedule, and you close the door this heist walked through.
What caused the Equifax breach? An unpatched website and an expired certificate: the case file and the Shorts from this case.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How the Capital One breach happened: one misconfigured cloud firewall
- What happened to Knight Capital: $460 million lost in 45 minutes
- How WannaCry hit the NHS: the fix existed 2 months before the attack
- How the Heartland breach happened: 130 million cards and an informant
- How the HSE cyber attack happened: one spreadsheet and 8 weeks of ignored alerts
- All episodes
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- U.S. Government Accountability Office: Data Protection: Actions Taken by Equifax and Federal Agencies in Response to the 2017 Breach (GAO-18-559)
- House Committee on Oversight and Government Reform: Committee Releases Report Revealing New Information on Equifax Data Breach
- House Committee on Oversight and Government Reform: The Equifax Data Breach (Majority Staff Report, December 2018)
- Federal Trade Commission: Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach
- U.S. Attorney's Office, Northern District of Georgia: Former Equifax employee sentenced for insider trading
- U.S. Department of Justice: Chinese Military Personnel Charged with Computer Fraud, Economic Espionage and Wire Fraud for Hacking into Credit Reporting Agency Equifax
- NPR: After Massive Data Breach, Equifax Directed Customers To Fake Site
- NBC News: Former Equifax CEO blames one IT guy for massive hack
- Help Net Security: Equifax breach happened because of a missed patch