One-line: A credit bureau left a known web-server flaw unpatched, and attackers stole the personal data of about 147 million people.
Highly sensitive personal records held by Equifax: names, Social Security numbers, birth dates, addresses, and some driver’s license and credit-card numbers.
A critical flaw in the Apache Struts web framework, tracked as CVE-2017-5638, which allowed remote code execution through a crafted HTTP request. A patch was released on March 7, 2017. Equifax did not apply it to all systems.
Around March 10, 2017, attackers exploited the unpatched flaw on Equifax’s online dispute portal. From May to July 2017 they quietly moved through the network and exfiltrated data on about 147 million people. Weak internal controls (poor network segmentation and an expired certificate on a monitoring tool) let the intrusion go unnoticed for about 76 days.
Mainly Confidentiality: private data was exposed to people who had no right to see it.
About 147 million people affected. Equifax agreed to a settlement of at least 575 million dollars (potentially up to 700 million) with the U.S. Federal Trade Commission, the Consumer Financial Protection Bureau, and the states in 2019.