{{short description|Major cybersecurity incident}} {{Use mdy dates|date=November 2020}}

Between May and July 2017, American credit bureau Equifax was breached. Private records of 147.9 million Americans along with 15.2 million British citizens and about 19,000 Canadian citizens were compromised in the breach, making it one of the largest cybercrimes related to identity theft. Equifax discovered the breach at the end of July, but did not disclose it to the public until September 2017. In a settlement with the United States Federal Trade Commission, Equifax offered affected users settlement funds and free credit monitoring.

In February 2020, the United States government indicted members of China's People's Liberation Army for hacking into Equifax and plundering sensitive data as part of a massive heist that also included stealing trade secrets, though the Chinese Communist Party denied these claims.<ref name="cbs china deny">{{cite web | url = https://www.cbsnews.com/news/china-denies-responsibility-in-equifax-breach-after-doj-charges-four-military-members/ | title = Data from Equifax credit hack could "end up on the black market," expert warns | date= February 11, 2020 | access-date = February 11, 2020 | work = CBS News }}</ref><ref name="WSJ Indicted">{{cite web | url = https://www.wsj.com/articles/four-members-of-china-s-military-indicted-for-massive-equifax-breach-11581346824 | title = Four Members of China's Military Indicted Over Massive Equifax Breach | date= February 11, 2020 | access-date = April 28, 2020 | work = The Wall Street Journal }}</ref>

==Data breach==

Information accessed in the breach included first and last names, Social Security numbers, birth dates, addresses, and, in some instances, driver's license numbers for an estimated 143 million Americans, based on Equifax' analysis.<ref name=":0">{{Cite web|url=https://www.cnbc.com/2017/09/07/credit-reporting-firm-equifax-says-cybersecurity-incident-could-potentially-affect-143-million-us-consumers.html|title=Credit reporting firm Equifax says cybersecurity incident could potentially affect 143 million US consumers|last=Haselton|first=Todd|date=September 7, 2017|website=cnbc.com|access-date=September 8, 2017}}</ref>

Information on almost 14 million British residents was also compromised,<ref>{{Cite web| url=https://www.fca.org.uk/publication/final-notices/equifax-limited-2023.pdf|title=FCA Final Notice 2023}} </ref> as well as 8,000 Canadian residents.<ref>{{cite news|last1=Shepardson|first1=David|title=Equifax failed to patch security vulnerability in March: former CEO|url=https://www.reuters.com/article/us-equifax-breach/equifax-failed-to-patch-security-vulnerability-in-march-former-ceo-idUSKCN1C71VY|newspaper=Reuters|agency=Reuters|access-date=October 3, 2017|date=October 2, 2017}}</ref><ref>{{cite web|last=Hern|first=Alex|url=https://www.theguardian.com/technology/2017/sep/08/equifax-told-to-inform-britons-whether-they-are-at-risk-after-data-breach|title=Equifax told to inform Britons whether they are at risk after data breach|work=The Guardian|date=September 8, 2017|access-date=September 11, 2017}}</ref><ref>{{cite news |url=https://www.thestar.com/business/2017/09/07/equifax-says-data-breach-may-affect-143-million-people-in-us.html |quote=Hackers targeted names, Social Security numbers, birth dates, addresses and driver's licence numbers, Equifax said in a statement. "Limited personal information" from residents in Canada and the U.K. was also accessed, it said. |first=Vjosa |last=Isai |date=September 7, 2017 |title=Canadians among 143 million people affected in Equifax hack |newspaper=The Toronto Star}}</ref><ref>{{Cite news|url=https://www.ctvnews.ca/business/article/equifax-says-100000-canadians-affected-by-cyberattack/|title=Equifax says 100,000 Canadians affected by cyberattack|last=Ligaya|first=Armina|date=September 19, 2017|work=CTVNews|access-date=September 21, 2017|language=en-CA}}</ref> An additional 11,670 Canadians were affected as well, later revealed by Equifax.<ref>{{Cite news|url=https://www.cbc.ca/news/business/equifax-canadians-affected-update-1.4424066|title=Equifax doubles number of Canadians hit by breach, now more than 19,000 {{!}} CBC News|work=CBC|access-date=June 23, 2018|language=en-US}}</ref> Credit card numbers for approximately 209,000 U.S. consumers, and certain dispute documents with personally identifiable information for approximately 182,000 U.S. consumers were also accessed.<ref>{{Cite web|url=https://www.equifaxsecurity2017.com/|title=Cybersecurity Incident & Important Consumer Information {{!}} Equifax|website=Cybersecurity Incident & Important Consumer Information|language=en-US|access-date=September 7, 2017}}</ref><ref name=":1" />

==Background== An Equifax internal audit in 2015 revealed a significant backlog of unresolved vulnerabilities. The audit found that Equifax was not adhering to its own patching schedules, IT staff lacked a comprehensive asset inventory, and the company did not prioritise patches based on the criticality of IT assets. Additionally, the patching process relied on an honour system, without strict enforcement. The report outlined actions to improve security measures, but by the time of the breach two years later, many had not been implemented.<ref>U.S. Senate Permanent Subcommittee on Investigations, Committee on Homeland Security and Governmental Affairs, “How Equifax Neglected Cybersecurity and Suffered a Devastating Data Breach,” March 6, 2019. Unclassified.</ref>

A key security patch for Apache Struts, a web application framework, was released on March 7, 2017, after a critical security vulnerability was identified, and all users of the framework were urged to update immediately.<ref>{{cite web |title=CVE-2017-5638 - Apache Struts2 S2-045 #8064 |date=March 7, 2017 |publisher=GitHub |url=https://github.com/rapid7/metasploit-framework/issues/8064 |access-date=September 16, 2017}}</ref> Security experts detected a hacking group of unidentified origin scanning for websites that had not updated Struts as early as March 10, 2017.<ref name="cnet"/>

==Intrusion== The Equifax data breach began on May 12, 2017, when Equifax had not yet updated its credit dispute website with the latest version of Apache Struts.<ref>{{cite web|last1=Whittaker|first1=Zack|title=Equifax confirms Apache Struts flaw it failed to patch was to blame for data breach|url=https://www.zdnet.com/article/equifax-confirms-apache-struts-flaw-it-failed-to-patch-was-to-blame-for-data-breach/|website=ZDNet|access-date=September 14, 2017|language=en}}</ref><ref>{{cite web|title=Failure to patch two-month-old bug led to massive Equifax breach|url=https://arstechnica.com/information-technology/2017/09/massive-equifax-breach-caused-by-failure-to-patch-two-month-old-bug/|website=Ars Technica|access-date=September 14, 2017|language=en-us|date=September 14, 2017}}</ref> Exploiting this vulnerability, hackers gained access to internal servers within Equifax's corporate network. Initially, they obtained internal credentials for Equifax employees, enabling them to access and query the credit monitoring databases while appearing as authorized users. Using encryption to further mask their searches, the hackers performed more than 9,000 scans of the databases. They extracted information into small temporary archives, exfiltrated them from Equifax servers to evade detection, and deleted the archives after extraction.<ref name="usa today how">{{cite web | url = https://www.usatoday.com/story/tech/2020/02/10/2017-equifax-data-breach-chinese-military-hack/4712788002/ | title = How Chinese military hackers allegedly pulled off the Equifax data breach, stealing data from 145 million Americans | first = Nathan | last = Bomey | date = February 10, 2020 | access-date = February 11, 2020 | work =USA Today }}</ref> The intrusion continued undetected for 76 days until July 29, 2017, when Equifax discovered the breach.<ref name="auto1">{{Citation|last=Equifax|title=Rick Smith, Chairman and CEO of Equifax, on Cybersecurity Incident Involving Consumer Data.|date=September 7, 2017|url=https://www.youtube.com/watch?v=bh1gzJFVFLc|access-date=September 12, 2017}}</ref><ref name=":0" /><ref name=":1">{{Cite web|url=https://investor.equifax.com/news-and-events/news/2017/09-15-2017-224018832|title=Equifax Releases Details on Cybersecurity Incident, Announces Personnel Changes|website=investor.equifax.com|language=en|access-date=September 16, 2017}}</ref> This breach was also largely possible due to the default username and password of "admin" and lack of two-factor authentication on high-access accounts. This let the hackers gain access with proper authentication to avoid detection as they continued with their exploits on the server. This, along with other major security violations, was the basis of the 2019 Class Action Lawsuit.<ref>{{cite web|url=https://www.bitdefender.com/en-us/blog/hotforsecurity/equifax-used-admin-as-username-and-password-internally|title="Equifax used "admin" as username and password internally"|date=April 4, 2025 }}</ref>

==Discovery== On July 29, 2017, Equifax's internal IT team updated a Secure Sockets Layer (SSL) certificate for an application that monitored inbound and outbound network traffic. The SSL certificate allowed the application to decrypt outgoing traffic to analyze it.<ref>{{cite web|url=https://sevenpillarsinstitute.org/case-study-equifax-data-breach/|title="Case Study: Equifax Data Breach"|date=April 30, 2021 }}</ref> Once the new SSL certificate was installed, the application alerted Equifax employees to suspicious network activity. The certificate had been expired for nine months.<ref> Kabanov, Ilya and Madnick, Stuart E., A Systematic Study of the Control Failures in the Equifax Cybersecurity Incident (2020). MIT Sloan Research Paper No. 2020-19, Available at SSRN: https://ssrn.com/abstract=3957272 or http://dx.doi.org/10.2139/ssrn.3957272 </ref>

By July 30, Equifax had shut down the exploit.<ref name="cnet">{{cite web | url = https://www.cnet.com/news/equifaxs-hack-one-year-later-a-look-back-at-how-it-happened-and-whats-changed/ | title = How the Equifax hack happened, and what still needs to be done | first= Alfred | last =Ng | date = September 7, 2018 | access-date = February 11, 2020 | work = CNet }}</ref> At least 34 servers in 20 different countries were used at various points during the breach, complicating efforts to track the perpetrators.<ref name="usa today how"/> While the failure to update Apache Struts was a significant issue, analysis of the breach identified additional security weaknesses that contributed to the incident. These included an insecure network design that lacked sufficient segmentation,<ref name="Newman">{{cite magazine|last1=Newman|first1=Lily Hay|title=How to Stop the Next Unstoppable Mega-Breach—Or Slow It Down|url=https://www.wired.com/story/how-to-stop-breaches-equifax|access-date=September 29, 2017|magazine=WIRED}}</ref> potentially inadequate encryption of personally identifiable information (PII),<ref name="Gallagher">{{cite news|last1=Gallagher|first1=Sean|title=Equifax hackers stole data for 200k credit cards from transaction history|url=https://arstechnica.com/information-technology/2017/09/equifax-hackers-stole-data-for-200k-credit-cards-from-transaction-history/|access-date=September 29, 2017|work=Ars Technica|language=en-us}}</ref> and ineffective breach detection mechanisms.<ref name="Lomas">{{cite news|last1=Lomas|first1=Natasha|title=Equifax breach disclosure would have failed Europe's tough new rules|url=https://techcrunch.com/2017/09/08/equifax-breach-disclosure-would-have-failed-europes-tough-new-rules/|access-date=September 29, 2017|work=TechCrunch|language=en}}</ref>

==Disclosure and short-term responses== On September 7, 2017, Equifax disclosed the breach and its scope, which affected over 140 million Americans.<ref>{{Cite web|url=https://www.forbes.com/sites/leemathews/2017/09/07/equifax-data-breach-impacts-143-million-americans/|title=Equifax Data Breach Impacts 143 Million Americans|last=Mathews|first=Lee|website=Forbes|language=en|access-date=August 28, 2019}}</ref> ''VentureBeat'' called the exposure of data on more than 140 million customers "one of the biggest data breaches in history."<ref>[https://venturebeat.com/2017/11/04/the-end-of-the-cloud-is-coming/ "The end of the cloud is coming"], VentureBeat, Victor Charypar, November 4, 2017</ref> Equifax shares dropped 13% in early trading the day after the breach was made public.<ref name="Bloomberg">{{Cite news|url=https://www.bloomberg.com/news/articles/2017-09-07/three-equifax-executives-sold-stock-before-revealing-cyber-hack|title=Three Equifax Managers Sold Stock Before Cyber Hack Revealed|last=Melin|first=Anders|date=September 7, 2017|work=Bloomberg.com|access-date=September 8, 2017}}</ref> Numerous media outlets advised consumers to request a credit freeze to reduce the impact of the breach.<ref>{{cite web|title=A Guide to Surviving the Equifax Data Breach|url=https://www.cnet.com/uk/how-to/a-guide-to-surviving-equifax-data-breach/|access-date=September 12, 2017|work=CNET}}</ref><ref>{{cite news|last1=Lieber|first1=Ron|date=September 10, 2017|title=After Equifax Breach, Here's Your Next Worry: Weak PINs|work=The New York Times|url=https://www.nytimes.com/2017/09/10/your-money/identity-theft/equifax-breach-credit-freeze.html|access-date=September 12, 2017}}</ref><ref>{{cite news|title=How to freeze your credit after a data breach|work=The Verge|url=https://www.theverge.com/2017/9/8/16276194/credit-freeze-equifax-how-to-data-breach|access-date=September 12, 2017}}</ref><ref>{{cite news|last1=Fung|first1=Brian|date=September 9, 2017|title=After the Equifax breach, here's how to freeze your credit to protect your identity|newspaper=The Washington Post|url=https://www.washingtonpost.com/news/the-switch/wp/2017/09/09/after-the-equifax-breach-heres-how-to-freeze-your-credit-to-protect-your-identity/}}</ref>

On September 10, 2017, three days after Equifax revealed the breach, Congressman Barry Loudermilk (R-GA), who had been given two thousand dollars in campaign funding from Equifax,<ref>{{cite web|last=Levin|first=Bess|title=Equifax Lobbied to Gut Regulations Right Before Getting Hacked|url=https://www.vanityfair.com/news/2017/09/equifax-lobbied-to-gut-regulations-right-before-hack|website=Vanityfair.com|date=September 12, 2017}}</ref><ref>{{cite web|title=Equifax Inc Contributions to Federal Candidates, 2016 cycle|url=https://www.opensecrets.org/pacs/pacgot.php?cmte=C00143867&cycle=2016|website=Opensecrets.org}}</ref> introduced a bill to the U.S. House of Representatives that would reduce consumer protections in relation to the nation's credit bureaus, including capping potential damages in a class action suit to $500,000 regardless of class size or amount of loss.<ref name="nbcweis">Weisbaum, Herb, [https://www.nbcnews.com/business/consumer/republicans-congress-want-roll-back-regulations-credit-bureaus-n800471 “Republicans in Congress Want to Roll Back Regulations on Credit Bureaus”], NBC News, September 11, 2017, Retrieved September 18, 2017</ref> The bill would also eliminate all punitive damages.<ref name="nbcweis" /><ref name="latimes_lazarus">{{cite news|last1=Lazarus|first1=David|date=September 19, 2017|title=Despite Equifax hack, GOP lawmakers want to deregulate credit agencies|work=Los Angeles Times|url=https://www.latimes.com/business/lazarus/la-fi-lazarus-republican-credit-agency-bills-20170919-story.html|access-date=September 20, 2017}}</ref> Following criticism by consumer advocates, Loudermilk agreed to delay consideration of the bill "pending a full and complete investigation into the Equifax breach".<ref name="nbcweis" />

On September 15, Equifax released a statement announcing the immediate departures and replacements of its chief information officer and chief security officer.<ref name=":1" /><ref>{{Cite news|last=Shaban|first=Hamza|date=September 15, 2017|title=Two Equifax executives will retire following massive data breach|language=en-US|newspaper=The Washington Post|url=https://www.washingtonpost.com/news/the-switch/wp/2017/09/15/two-equifax-executives-will-retire-following-massive-data-breach/|access-date=September 17, 2017|issn=0190-8286}}</ref> The statement included bullet-point details of the intrusion, its potential consequences for consumers, and the company's response. The company said it had hired cybersecurity firm Mandiant on August 2 to investigate the intrusion internally. The statement did not specify when U.S. government authorities were notified of the breach, although it did assert "the company continues to work closely with the FBI in its investigation".<ref name=":1" />

On September 26, Equifax announced the retirement of CEO Richard Smith, 57, who agreed to remain as an unpaid advisor to assist in the transition to a new CEO.<ref>{{cite web |title=Equifax Chairman, CEO, Richard Smith Retires; Board of Directors Appoints Current Board Member Mark Feidler Chairman; Paulino do Rego Barros, Jr. Appointed Interim CEO; Company to Initiate CEO Search |url=https://investor.equifax.com/news-events/press-releases/detail/236/equifax-chairman-ceo-richard-smith-retires-board-of |website=Equifax Investor Relations |access-date=23 November 2024}}</ref><ref>{{cite journal |last1=Rushe |first1=Dominic |title=Equifax chief Richard Smith steps down in wake of massive data breach |journal=The Guardian |date=26 September 2017 |url=https://www.theguardian.com/business/2017/sep/26/equifax-boss-richard-smith-retires-data-breach |access-date=23 November 2024}}</ref>

On September 28, new Equifax CEO Paulino do Rego Barros Jr. responded to criticism of Equifax by promising that the company would, from early 2018, allow "all consumers the option of controlling access to their personal credit data", and that this service would be "offered free, for life".<ref>{{cite web|url=https://arstechnica.co.uk/tech-policy/2017/09/equifax-ceo-apology/|title=New Equifax CEO offers "sincere and total apology" to consumers|access-date=October 20, 2017|date=September 28, 2017}}</ref>

On October 26, Equifax appointed technology executive Scott A. McGregor to its board of directors. In announcing the change, the board's chairman noted McGregor's "extensive data security, cybersecurity, information technology and risk management experience".<ref>{{cite press release|publisher=Equifax |title=Equifax Names Scott McGregor as New Independent Director|date=October 26, 2017|via=PRNewswire|location=Atlanta, Georgia|url=https://www.prnewswire.com/news-releases/equifax-names-scott-mcgregor-as-new-independent-director-300543942.html|access-date=June 20, 2020}}</ref><ref name=":3">{{Cite web|date=November 6, 2017|title=Cybersecurity Expert Scott McGregor Joins Equifax Board|url=https://www.equilar.com/blogs/329-cybersecurity-expert-scott-mcgregor-joins-equifax-board.html|access-date=June 21, 2020|website=www.equilar.com|language=en}}</ref> ''The Wall Street Journal'' reported that he joined the board's technology committee, which has duties that include oversight of cybersecurity.<ref>{{cite news|last1=Nash|first1=Kim S.|last2=Lublin|first2=Joann S.|last3=Andriotis|first3=AnnaMaria|date=January 10, 2018|title=Boards Seek Bigger Role in Thwarting Hackers: Equifax breach triggered broad reassessment of cybersecurity oversight, experts say|newspaper=The Wall Street Journal|url=https://www.wsj.com/articles/boards-seek-bigger-role-in-thwarting-hackers-1515596400|access-date=June 20, 2020}}</ref>

==Aftermath==

Since the initial disclosure in September 2017, Equifax expanded the number of records they discovered were accessed. In both October 2017 and March 2018, Equifax reported that an additional 2.5 and 2.4 million American consumer records were accessed, respectively, bringing the total to 147.9 million.<ref>{{cite web |last1=Weise |first1=Elizabeth |last2=Bomey |first2=Nathan |url=https://www.usatoday.com/story/tech/2017/10/02/equifax-breach-hit-2-5-million-more-americans-than-first-believed/725100001/ |title=Equifax breach hit 2.5 million more Americans than first believed |date=October 2, 2017 |work=USA Today |access-date=October 4, 2017}}</ref><ref>[https://www.forthepeople.com/class-action-lawyers/equifax-data-breach-lawsuit/ "Equifax Data Breach Lawsuit"], ''Morgan & Morgan''.</ref> Equifax narrowed its estimate for UK consumers affected by the breach to 15.2 million in October 2017,<ref name="reut-10-10">{{cite news|url=https://www.reuters.com/article/us-equifax-cyber/equifax-says-15-2-million-uk-records-accessed-in-cyber-breach-idUSKBN1CF2JU|title=Equifax says 15.2 million UK records exposed in cyber breach|date=October 10, 2017|access-date=October 11, 2017|work=Reuters}}</ref><ref name="ukncsc-2017-10">{{cite web|url=https://www.ncsc.gov.uk/information/latest-information-equifax-cyber-incident|title=Latest information on the Equifax cyber incident - NCSC Site|website=www.ncsc.gov.uk|access-date=October 13, 2017}}</ref> of which 693,665 had sensitive personal data disclosed.<ref>{{cite web|url=https://krebsonsecurity.com/2017/10/equifax-hackers-stole-info-on-693665-uk-residents/|title=Equifax Hackers Stole Info on 693,665 UK Residents — Krebs on Security|website=krebsonsecurity.com|date=October 10, 2017 |access-date=October 11, 2017}}</ref><ref>{{cite web|url=https://www.theguardian.com/technology/2017/oct/11/personal-details-of-almost-700000-britons-hacked-in-cyber-attack|title=Personal details of almost 700,000 Britons hacked in cyber-attack|last1=Staff|last2=agencies|date=October 11, 2017|access-date=October 11, 2017|website=Theguardian.com}}</ref><ref name="reut-10-10"/><ref>{{cite web|url=https://www.bbc.co.uk/news/business-41575188|title=Equifax hack hit 694,000 UK customers|date=October 10, 2017|access-date=October 11, 2017|website=bbc.co.uk}}</ref><ref name="ukncsc-2017-10"/> Equifax also estimated that the number of drivers' licenses breached in the attack to be 10-11 million.<ref>{{cite web|url=https://www.msn.com/en-us/money/us/equifax-breach-exposed-driver%E2%80%99s-license-data-for-11-million-americans/vp-AAtiY9c|title=Equifax Breach Exposed Driver's License Data for 11 Million Americans|website=www.msn.com|access-date=October 13, 2017}}</ref><ref>{{cite web|url=http://mashable.com/2017/10/11/equifax-hackers-got-drivers-licenses/|title=On top of everything else, Equifax hackers got 10 million driver's licenses|first=Monica|last=Chin|website=Mashable.com|date=October 11, 2017|access-date=October 13, 2017}}</ref><ref>{{cite web|url=https://www.cnet.com/news/equifax-hackers-took-10-million-americans-drivers-license-info/|title=Equifax hackers took driver's license info on 10M Americans|website=Cnet.com|access-date=October 13, 2017}}</ref>

Security experts expected that the lucrative private data from the breach would be turned around and sold on black markets and the dark web, though as of May 2021, there has been no sign of any sale of this data.<ref name="cbs china deny"/> Because the data did not immediately show up in the first 17 months following the breach, security experts theorized that either the hackers behind the breach were waiting for a significant amount of time before selling the information since it would be too "hot" to sell that close to the breach, or that a nation-state was behind the breach and planning on using the data in a non-financial manner such as for espionage.<ref>{{cite web | url = https://www.cnbc.com/2019/02/13/equifax-mystery-where-is-the-data.html | title = The great Equifax mystery: 17 months later, the stolen data has never been found, and experts are starting to suspect a spy scheme | first = Kate | last = Fazzini | date = February 13, 2020 | access-date = February 11, 2020 |work = CNBC }}</ref>

==Litigation and fines== Numerous lawsuits were filed against Equifax in the days after the disclosure of the breach.<ref name="BGR">{{Cite news|url=http://bgr.com/2017/09/08/equifax-hack-lawsuit-class-action-how-to-join/|title=Equifax is already facing the largest class-action in history|last=Mills|first=Chris|date=September 8, 2017|work=bgr.com|access-date=September 8, 2017}}</ref><ref name="SFGate">{{cite news|last1=Thadani|first1=Trisha|title=Lawsuit against Equifax filed in federal court in San Jose|url=http://m.sfgate.com/business/article/Lawsuit-against-Equifax-filed-in-federal-court-in-12192966.php|access-date=September 13, 2017|work=SFGate.com|date=September 13, 2017}}</ref> In one suit the law firm Geragos & Geragos has indicated they would seek up to $70 billion in damages, which would make it the largest class-action suit in U.S. history.<ref name="BGR"/> Since October 2017, hundreds of consumers have sued Equifax for the data breach, some winning small claims cases in excess of $9,000, including actual damages, future damages, anxiety, monitoring fees and punitive damages.<ref>{{Cite web|url=https://finance.yahoo.com/news/people-successfully-suing-equifax-almost-10000-app-193607932.html|title=People are taking Equifax to small-claims court — and winning|website=finance.yahoo.com|date=January 31, 2018 }}</ref>

In September 2017, Richard Cordray, then director of the Consumer Financial Protection Bureau (CFPB), authorized an investigation into the data breach on behalf of affected consumers. However, in November 2017, Mick Mulvaney, President Donald Trump's budget chief, who was appointed by Trump to replace Cordray, was reported by Reuters to have "pulled back" on the probe, along with shelving Cordray's plans for on-the-ground tests of how Equifax protects data. The CFPB also rebuffed bank regulators at the Federal Reserve Bank, Federal Deposit Insurance Corporation and Office of the Comptroller of the Currency who offered to assist with on-site exams of credit bureaus.<ref>Patrick Rucker, [https://www.reuters.com/article/us-usa-equifax-cfpb/exclusive-u-s-consumer-protection-official-puts-equifax-probe-on-ice-sources-idUSKBN1FP0IZ “U.S. consumer protection official puts Equifax probe on ice”], Reuters, February 5, 2018, Retrieved February 16, 2018</ref> Senator Elizabeth Warren, who released a report on the Equifax breach in February 2018, criticized Mulvaney's actions, stating: "We're unveiling this report while Mick Mulvaney is killing the consumer agency's probe into the Equifax breach. Mick Mulvaney shoots another middle finger at consumers."<ref>{{cite news|url=https://www.vox.com/policy-and-politics/2018/2/7/16984522/elizabeth-warren-equifax-data-breach-cfpb|title=Elizabeth Warren warns Equifax could "wiggle off the hook" for users' credit data getting hacked|last=Stewart|first=Emily|date=February 7, 2018|website=Vox|access-date=February 16, 2018}}</ref>

On July 22, 2019, Equifax agreed to a settlement with the Federal Trade Commission (FTC), CFPB, 48 U.S. states, Washington, D.C., and Puerto Rico to alleviate damages to affected individuals and make organizational changes to avoid similar breaches in the future. The total cost of the settlement included $300 million to a fund for victim compensation, $175 million to the states and territories in the agreement, and $100 million to the CFPB in fines.<ref>{{Cite web|url=https://www.ftc.gov/news-events/press-releases/2019/07/equifax-pay-575-million-part-settlement-ftc-cfpb-states-related|title=Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach|date=July 19, 2019|website=Federal Trade Commission|language=en|access-date=July 25, 2019}}</ref> In July 2019, the FTC published information on how affected individuals could file a claim against the victim compensation fund using the website [https://www.EquifaxBreachSettlement.com EquifaxBreachSettlement.com].<ref>{{Cite web|url=https://www.ftc.gov/enforcement/cases-proceedings/refunds/equifax-data-breach-settlement|title=Equifax Data Breach Settlement|date=July 11, 2019|website=Federal Trade Commission|language=en|access-date=July 25, 2019}}</ref>

In the UK, the Financial Conduct Authority imposed a financial penalty of £11,164,400 for failing to protect the information of UK consumers.<ref>{{Cite web| url=https://www.fca.org.uk/publication/final-notices/equifax-limited-2023.pdf|title=FCA Final Notice 2023}} </ref>

==Perpetrators== The United States Department of Justice announced on February 10, 2020 that they had indicted four members of China's military on nine charges related to the hack, though there has been no additional evidence that China has since used the data from the hack.<ref>{{cite web | url = https://www.nytimes.com/2020/02/10/us/politics/equifax-hack-china.html | title = U.S. Charges Chinese Military Officers in 2017 Equifax Hacking | first= Katie | last = Benner | date = February 10, 2020 | access-date = February 10, 2020 | work = The New York Times }}</ref><ref>{{cite web |last1=Mariam |first1=Baksh |title=Chinese Military Officers Hacked Equifax, Justice Department Says |url=https://www.defenseone.com/technology/2020/02/chinese-military-officers-hacked-equifax-justice-department-says/163013/?oref=d-river |website=www.defenseone.com |date=February 10, 2020 |publisher=Defense One |access-date=February 25, 2020}}</ref><ref>{{Cite web|url=https://www.technologyreview.com/2020/02/10/349004/the-us-says-the-chinese-military-hacked-equifax-heres-how/|title = The US says the Chinese military hacked Equifax. Here's how}}</ref> The Chinese government denied that the four accused had any involvement with the hack.<ref name="cbs china deny"/>

==Criticism== Following the announcement of the May–July 2017 breach, Equifax's actions received widespread criticism. Equifax did not immediately disclose whether PINs and other sensitive information were compromised, nor did it explain the delay between its discovery of the breach in July and its public announcement in early September.<ref>{{Cite web|url=https://www.inc.com/joseph-steinberg/6-unanswered-questions-for-equifax-after-a-massive.html|title=6 Unanswered Questions For Equifax After A Massive Data Breach Of 143-Million Americans' Personal Information|language=en-US|access-date=September 8, 2017|date=September 8, 2017}}</ref> Equifax stated that the delay was due to the time needed to determine the scope of the intrusion and the large amount of personal data involved.<ref name="equifax-security-faqs">{{cite web|title=Cybersecurity Incident & Important Consumer Information|url=https://www.equifaxsecurity2017.com/frequently-asked-questions/|website=equifaxsecurity2017.com|publisher=Equifax|access-date=September 13, 2017|date=2017}}</ref>

It was also revealed that three Equifax executives sold almost $1.8 million of their personal holdings of company shares days after Equifax discovered the breach but more than a month before the breach was made public.<ref>{{Cite news|url=https://www.bloomberg.com/news/articles/2017-09-07/three-equifax-executives-sold-stock-before-revealing-cyber-hack|title=Three Equifax Managers Sold Stock Before Cyber Hack Revealed|last=Melin|first=Anders|date=September 7, 2017|newspaper=Bloomberg.com|access-date=September 7, 2017}}</ref> The company said the executives, including the chief financial officer John Gamble,<ref name="guardian">{{cite news|url=https://www.theguardian.com/us-news/2017/sep/07/equifax-credit-breach-hack-social-security|title=Credit firm Equifax says 143m Americans' social security numbers exposed in hack|last=Solon|first=Olivia|date=September 7, 2017|work=The Guardian|access-date=September 11, 2017}}.</ref><ref name="Bloomberg" /> "had no knowledge that an intrusion had occurred at the time they sold their shares".<ref>{{cite news|url=https://www.telegraph.co.uk/technology/2017/09/08/equifax-hack-britons-data-watchdog-investigates-ukimpact-major/|title=Equifax hack: 44 million Britons' personal details feared stolen in major US data breach|last=Morley|first=Katie|date=September 8, 2017|work=The Daily Telegraph|access-date=September 9, 2017}}</ref> On September 18, ''Bloomberg'' reported that the U.S. Justice Department had opened an investigation to determine whether or not insider trading laws had been violated.<ref>{{Cite news|url=https://www.bloomberg.com/news/articles/2017-09-18/equifax-stock-sales-said-to-be-focus-of-u-s-criminal-probe|title=Equifax Stock Sales Are the Focus of U.S. Criminal Probe|date=September 18, 2017|work=Bloomberg.com|access-date=September 18, 2017}}</ref> "As Bloomberg notes, these transactions were not pre-scheduled trades and they took place on August 2, three days after the company learned of the hack".

When publicly revealing the intrusion to its systems, Equifax offered a website (<nowiki>https://www.equifaxsecurity2017.com</nowiki><ref>{{Cite news |url=https://money.cnn.com/2017/09/11/pf/equifaxmyths/index.html |archive-url=https://web.archive.org/web/20170912022521/http://money.cnn.com/2017/09/11/pf/equifaxmyths/index.html |url-status=dead |archive-date=September 12, 2017 |title=6 Equifax hack rumors fact-checked |last=Bahney |first=Anna |work=CNNMoney |access-date=September 12, 2017}}</ref>) for consumers to learn whether they were victims of the breach. Security experts quickly noted that the website had many traits in common with a phishing website: it was not hosted on a domain registered to Equifax, it had a flawed TLS implementation, and it ran on WordPress which is not generally considered suitable for high-security applications. These issues led Open DNS to classify it as a phishing site and block access.<ref name="ars">{{cite news|url=https://arstechnica.com/information-technology/2017/09/why-the-equifax-breach-is-very-possibly-the-worst-leak-of-personal-info-ever/|title=Why the Equifax breach is very possibly the worst leak of personal info ever|publisher=CNBC|access-date=September 10, 2017}}</ref> Moreover, members of the public wanting to use the Equifax website to learn if their data had been compromised had to provide a last name and six digits of their social security number.<ref name="cnet-hack-checker" />

The website set up to check whether a person's personal data had been breached (<nowiki>trustedidpremier.com</nowiki>) was determined by security experts and others to return apparently random results instead of accurate information.<ref name="cnet-hack-checker">{{cite web|url=https://www.cnet.com/uk/how-to/psa-equifaxs-hack-checker-is-a-hot-mess/|title=Equifax's hack checker is a hot mess -- here's what to do|website=Cnet.com|access-date=September 10, 2017}}</ref> As with <nowiki>https://www.equifaxsecurity2017.com</nowiki>, this website, too, was registered and constructed like a phishing website, and it was flagged as such by several web browsers.<ref>{{cite news|last1=Krebs|first1=Brian|title=Equifax or Equiphish? — Krebs on Security|url=https://krebsonsecurity.com/2017/09/equifax-or-equiphish/|access-date=October 13, 2017|work=krebsonsecurity.com}}</ref>

The Trusted ID Premier website contained terms of use, dated September 6, 2017 (the day before Equifax announced the security breach) which included an arbitration clause with a class action waiver.<ref name="chacos">{{cite web|last1=Chacos|first1=Brad|title=Equifax hack: How to know if you're affected|url=https://www.pcworld.com/article/3223142/security/equifax-hack-how-to-know-affected-data-breach.html|website=PCWorld|access-date=September 13, 2017|date=September 8, 2017}}</ref><ref name="robertson">{{cite web |url=https://www.theverge.com/2017/9/8/16276572/equifax-hack-protection-class-action-lawsuit-terms-of-service |website=The Verge |title=Can you join a class action suit if you use Equifax's free identity theft protection? |first=Adi |last=Robertson |date=September 8, 2017}}</ref> Attorneys said that the arbitration clause was ambiguous and that it could require consumers who accepted it to arbitrate claims related to the cybersecurity incident.<ref name="robertson" /> According to Polly Mosendz and Shahien Nasiripour, "some fear[ed] that simply using an Equifax website to check whether their information was compromised bound them to arbitration".<ref name="mosendz-nasiripour">{{cite news|last1=Mosendz|first1=Polly |last2=Nasiripour| first2=Shahien|title=Equifax's Hacking Nightmare Gets Even Worse For Victims|url=https://www.bloomberg.com/news/articles/2017-09-08/equifax-s-hacking-nightmare-gets-worse-thanks-to-arbitration-clause|website=Bloomberg.com|access-date=September 13, 2017|date=September 8, 2017}}</ref> The equifax.com website has separate terms of use with an arbitration clause and class action waiver, but, according to Brian Fung of ''The Washington Post'', "it's unclear if that applies to the credit monitoring program".<ref name="fung-tribune">{{cite web|last1=Fung|first1=Brian|title=By signing up on Equifax's help site, you risk giving up your legal rights|url=https://www.chicagotribune.com/business/ct-equifax-data-breach-website-arbitration-20170908-story.html|website=chicagotribune.com|access-date=September 13, 2017|date=September 8, 2017}}</ref> New York Attorney General Eric Schneiderman demanded that Equifax remove the arbitration clause.<ref name="fung" /> Responding to arbitration-related concerns, on September 8, Equifax issued a statement stating that "in response to consumer inquiries, we have made it clear that the arbitration clause and class action waiver included in the Equifax and TrustedID Premier terms of use does not apply to this cybersecurity incident".<ref name="fung">{{Cite news|url=https://www.washingtonpost.com/news/the-switch/wp/2017/09/08/what-to-know-before-you-check-equifaxs-data-breach-website/|title=Equifax finally responds to swirling concerns over consumers' legal rights|newspaper=The Washington Post|language=en-US|access-date=September 8, 2017}}</ref> Joel Winston, a data protection lawyer, argued that the announcement disclaiming the arbitration clause "means nothing" because the terms of use state that they are the "entire agreement" between the parties.<ref name="fung" /> The arbitration clause was later removed from equifaxsecurity2017.com,<ref name="fung" /> and the equifax.com terms of use were amended on September 12 to state that they do not apply to www.equifaxsecurity2017.com, www.trustedidpremier.com, or www.trustedid.com and to exclude claims arising from those sites or the security breach from arbitration.<ref name="equifax-consumer-faq">{{cite web|author1=Equifax|title=Frequently Asked Questions - Cybersecurity Incident & Important Consumer Information {{!}} Equifax|url=https://www.equifaxsecurity2017.com/frequently-asked-questions/#consumer-faqs|website=2017 Cybersecurity Incident & Important Consumer Information|access-date=February 16, 2018|quote=When were the Terms of Use for TrustedID Premier updated? ... We updated the Equifax product Terms of Use on www.equifax.com on September 12, 2017 to state that those terms do not apply to the TrustedID Premier product or the cybersecurity incident}}</ref><ref name="equifax-terms-of-use">{{cite web|author1=Equifax|title=Terms of Use|url=https://www.equifax.com/terms/|website=equifax.com|access-date=February 16, 2018|archive-url=https://web.archive.org/web/20170915194554/https://www.equifax.com/terms/|date=September 12, 2017|archive-date=September 15, 2017}}</ref>

Responding to continuing public outrage,<ref name="nydailynews">{{cite web|title=What Equifax owes us all: A free credit freeze at all agencies, for starters, and loads of answers|url=http://www.nydailynews.com/opinion/equifax-owes-article-1.3490673|website=New York Daily News|access-date=September 13, 2017|date=September 12, 2017}}</ref> Equifax announced on September 12, 2017, that they "are waiving all Security Freeze fees for the next 30 days".<ref name="freezefee">{{cite web|last1=Kirsch|first1=Melissa|title=Equifax Is Waiving Their Credit-Freeze Fees for 30 Days|url=http://lifehacker.com/equifax-is-waiving-their-credit-freeze-fees-for-30-days-1805663077|website=lifehacker|access-date=September 13, 2017|date=September 12, 2017}}</ref><ref>{{cite web |last1=Hatmaker |first1=Taylor |title=Equifax says that it will waive credit freeze fees for 30 days |url=https://techcrunch.com/2017/09/12/will-equifax-waive-credit-freeze-fees/?guccounter=1&guce_referrer=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS8&guce_referrer_sig=AQAAAD2zpeNQ6JWn5CgncoI7SXayxN9_H9fkOEoIl3lf7AlVsjo2AII1jpwdfqu9QH8VEBieAgXT-qqarxAz-bpkdZQE4A8yhlv_b-Fil6EbrCOy6eaduSVx90vhsLeiKcXKmb2a-Eh2HCymKTu-nDrIqSrOALLGokFK-XXaXC8AnNgO |website=TechCrunch|date=September 12, 2017 }}</ref>

Equifax has been criticized by security experts for registering a new domain name for the site name instead of using a subdomain of <code>equifax.com</code>. On September 20, 2017, it was reported that Equifax had been mistakenly linking to an unofficial "fake" web site instead of their own breach notification site in at least eight separate tweets, unwittingly helping to direct a reported 200,000 hits to the imitation site. A software engineer named Nick Sweeting created the unauthorized Equifax web site to demonstrate how the official site could easily be confused with a phishing site.<ref>{{cite web |last1=Sweeting |first1=Nick |title=Equifax Security Incident (2017) |url=https://docs.sweeting.me/s/equifax-security-incident# |archive-url=https://web.archive.org/web/20240824143940/https://docs.sweeting.me/s/equifax-security-incident |archive-date=24 August 2024}}</ref> Sweeting's site was upfront to visitors that it was not official, however, telling visitors who had entered sensitive information that "you just got bamboozled! this isnt {{sic}} a secure site! Tweet to @equifax to get them to change it to equifax.com before thousands of people loose {{sic}} their info to phishing sites!" Equifax apologized for the "confusion" and deleted the tweets linking to this site.<ref>{{Cite news|url=https://www.nytimes.com/2017/09/20/business/equifax-fake-website.html|title=Someone Made a Fake Equifax Site. Then Equifax Linked to It.|last=Astor|first=Maggie|date=September 20, 2017|work=The New York Times|access-date=September 21, 2017|language=en-US|issn=0362-4331}}</ref><ref>{{cite web|title=Equifax sends breach victims to fake notification site|url=https://arstechnica.com/information-technology/2017/09/equifax-directs-breach-victims-to-fake-notification-site/|website=Ars Technica|date=September 20, 2017 |access-date=September 21, 2017|language=en-us}}</ref><ref>{{Cite news|url=http://mashable.com/2017/09/20/equifax-twitter-phishing-site-facepalm|title=Equifax has been directing victims to a fake phishing site for weeks|last=Morse|first=Jack|work=Mashable|access-date=September 21, 2017|language=en}}</ref>

==See also== * Chinese cyberwarfare * Chinese espionage in the United States

==References== {{reflist}}

{{Hacking in the 2010s}}

{{DEFAULTSORT:Equifax data breach, 2017}} Category:Data breaches in the United States Category:2017 controversies in the United States Category:2017 data breaches Category:May 2017 crimes in the United States Category:June 2017 crimes in the United States Category:July 2017 crimes in the United States Category:September 2017 in the United States Category:2010s in hacking Category:Identity theft incidents Category:Internet privacy