EQUIFAX▊
Organization dossier 2017 data breach · ~147M people Status: still operating
A credit bureau that held the financial histories of roughly 147 million Americans — people who never signed up to be its product — left a known-critical web-server hole unpatched for months after the fix shipped, got quietly ransacked for 76 days, then waited about six weeks to tell anyone. In that gap, two of its own employees traded on the secret. One was its U.S. chief information officer. Both were convicted.
To each and every person affected by this breach, I am deeply sorry that this occurred … The people affected by this are not numbers in a database. They are my friends, my family, members of my church, members of my community, my neighbors.
Former CEO Richard F. Smith, testifying to Congress, October 2017, per the official hearing transcript
This comprehensive settlement is a positive step for U.S. consumers and Equifax as we move forward from the 2017 cybersecurity incident … reinforc[ing] our commitment to putting consumers first and safeguarding their data.
CEO Mark W. Begor, in Equifax's own announcement of the 2019 settlement, investor.equifax.com
- ENTITY
- Equifax Inc., Atlanta, Georgia — one of the three nationwide consumer credit-reporting agencies FACT
- THE HOLE
- Apache Struts flaw CVE-2017-5638 — patch released Mar 7, 2017; US-CERT notified Equifax Mar 8; the affected portal stayed unpatched FACT
- THE BREACH
- Attackers inside from mid-May 2017 to discovery on Jul 29, 2017 — roughly 76 days undetected; ~147M Americans (plus UK and Canadian records) exposed FACT
- THE DELAY
- Discovered Jul 29; disclosed to the public Sep 7, 2017 — about six weeks later
- THE CONVICTIONS
- Two employees pleaded guilty to insider trading ahead of disclosure: Jun Ying (CIO, a U.S. unit) and Sudhakar Reddy Bonthu (a manager) FACT
- THE CHECK
- ~$575M, up to $700M — the 2019 global settlement with the FTC, CFPB, and 50 states & territories FACT
- STATUS
- STILL OPERATING — still one of the big three; still holds the file on you
This one is a company, not a person — and the distinction does real work on this page. A company can be careless with 147 million files and answer for it in a settlement. Only individuals can be convicted of a crime, and exactly two were. Keep those separate; this file does.
It is impossible for a normal human to keep track of what happened when. That is why the archive exists. Every beat below carries its receipt. Both sides get the microphone. You decide who wins.
the drama timeline
ACT I — THE PATCH NOBODY APPLIED (MAR–JUL 2017)
Every breach of this kind begins with a door that was known to be open, a notice that it was open, and a stretch of quiet in which nobody closed it. Here is that stretch.
-
MAR 7–8, 2017
The fix ships. The warning arrives.
The Apache Software Foundation releases a patch for CVE-2017-5638, a critical remote-code-execution flaw in Apache Struts. The next day, US-CERT notifies Equifax of the vulnerability; the company circulates the alert internally. The patch is not applied to the vulnerable consumer-dispute portal.
-
MAY–JUL 2017
76 days inside
From roughly mid-May 2017, attackers move through Equifax systems and exfiltrate data. The activity runs undetected until July 29, 2017, when Equifax security personnel finally spot the suspicious traffic and begin blocking it — about 76 days after the intrusion began. An expired certificate on a monitoring device is later cited as one reason the traffic went unseen for so long.
A company whose entire product is telling banks whether you can be trusted to guard a financial obligation did not notice strangers inside its own vault for two and a half months.
ACT II — THE SIX WEEKS (JUL 29 – SEP 7, 2017)
Between knowing and telling, six weeks pass. Watch what moves in that gap, and what does not.
-
AUG 1–2, 2017
Executives sell — and are later cleared
Days after the intrusion is discovered but weeks before the public is told, four Equifax executives — CFO John Gamble and three others — sell company shares (three of the sales, widely reported at about $1.8 million). Equifax says they were unaware of the breach when they traded. On November 3, 2017, an independent board Special Committee reports that none of the four had knowledge of the incident when the trades were made, that pre-clearance was properly obtained, and that none engaged in insider trading. None of the four is charged.
-
SEP 7, 2017
The disclosure — and the site that broke
Equifax publicly discloses the breach — roughly six weeks after discovering it — affecting about 147 million U.S. consumers (later put at 147.9 million), plus UK and Canadian records. The company stands up a check-your-status site, equifaxsecurity2017.com, on a domain not registered to Equifax, running WordPress, with a flawed TLS setup; it asks visitors to hand over a last name and six digits of their Social Security number. Equifax's own official Twitter account repeatedly directs users to a phishing look-alike of the site by mistake.
To find out whether the credit bureau had lost control of your identity, it asked you to type more of your identity into a WordPress box it forgot to register in its own name.
ACT III — THE RECKONING (SEP–OCT 2017)
When a display fails this publicly, someone is put forward to answer for it. The company sends its leadership to the microphone and, shortly after, into retirement.
-
SEP 26, 2017
The retirements
Equifax announces the retirement of Chairman and CEO Richard Smith, 57 — days after the departures of its chief information officer and chief security officer. The board says Smith forgoes his 2017 bonus; the size of his overall exit package becomes its own line of congressional questioning.
-
OCT 2017
Smith answers to Congress
Smith testifies before multiple congressional committees. He apologizes — "I am deeply sorry that this breach occurred on my watch" — and attributes it to "human error and technology failures," including a single employee's failure to heed the patch notice and a scanner that did not detect the vulnerable system. The apology is his; so is the explanation.
ACT IV — THE CONVICTIONS AND THE CHECK (2018–2019)
The company settles. The individuals are tried. These are different proceedings with different burdens, and the record keeps them apart.
-
MAR 2018 – 2019
Jun Ying, convicted
The SEC charges Jun Ying — CIO of a U.S. Equifax business unit and next in line to be global CIO — with insider trading, alleging he used confidential information to conclude Equifax was the breached company, then exercised and sold his options before the public knew. Per the Justice Department, Ying had texted a colleague that the incident they were working "sounds bad. We may be the one breached," and reaped proceeds of nearly $1 million. Ying pleads guilty in March 2019 and is sentenced to four months in prison, restitution, and a fine.
-
2018–2019
And a second: Sudhakar Reddy Bonthu
A second employee is charged and convicted. Sudhakar Reddy Bonthu, an Equifax software-development manager who helped build the breach-response site, bought put options on Equifax stock before disclosure — against company policy — and cleared more than $75,000. He pleads guilty and is sentenced to eight months of home confinement, a fine, and forfeiture. Two convictions; both were individuals acting for themselves.
-
JUL 22, 2019
The record settlement
Equifax reaches a global settlement with the FTC, the CFPB, and 50 states and territories: at least $575 million, rising to as much as $700 million. It includes a consumer fund of up to $425 million, a $100 million CFPB civil penalty, and free credit monitoring. Equifax does not admit liability. At the time it is the largest data-breach settlement on record.
-
EPILOGUE
Still operating
Equifax remains one of the three nationwide credit bureaus. It still holds the financial file on nearly every adult American, most of whom never chose to be in it. The settlement is paid; the convictions are served; the company files quarterly earnings. The archive keeps the tape running.
both sides, on the record
The negligence is documented: the patch for CVE-2017-5638 shipped March 7, 2017 and US-CERT warned Equifax the next day; the vulnerable portal stayed unpatched, and attackers roamed undetected for roughly 76 days [1] [8] [10].
The delay and the theater: Equifax knew on July 29 and told the public about six weeks later, on September 7 — then routed frightened consumers to a check-your-status site it had not even registered in its own name, and asked them to surrender more identity data to find out if their identity was already gone [8] [10].
Two insiders were convicted: its U.S. CIO (Jun Ying) and a software manager (Bonthu) each pleaded guilty to trading Equifax stock ahead of the disclosure — criminal convictions, on the DOJ and SEC record [4] [6] [9].
The state agreed it went wrong: the record $575–700M settlement with the FTC, CFPB, and 50 states is the government's own assessment that consumers were harmed [2] [3].
A breach can happen to anyone, and the crimes were individual, not corporate. The two convictions were of employees acting for themselves and against company policy — not the company trading on its customers. Equifax reported the breach to law enforcement and cooperated [6] [9].
The executive stock sales were cleared — on the record. The senior executives who sold shares in early August were reviewed by an independent board Special Committee, which found they had no knowledge of the breach when they traded, that pre-clearance was properly obtained, and that none engaged in insider trading. None of them was ever charged [12] [13]. This page asserts no motive against them and no wrongdoing they were not found to have committed.
Remediation and no admission of liability. Equifax settled without admitting wrongdoing, funded up to $425 million in consumer relief plus free credit monitoring, replaced its leadership, and says it has since spent heavily overhauling its security. In its CEO's own words, the settlement "reinforces our commitment to putting consumers first and safeguarding their data" [2] [14].
Scope of the record: no court has found the company itself criminally liable; the settlement is a civil resolution, not an adjudication of fraud. The wrongdoing proven beyond doubt is that of two individuals, and the record names them and stops there.
YOU DECIDE
Scoped to the claims, never smuggled into motive. The claim "Equifax was negligent with 147 million people's data" is about as documented as such a claim gets: a known-critical patch left unapplied after a federal warning, 76 days of undetected theft, a six-week disclosure delay, a notification site that was itself a security incident, and a record government settlement. The claim "Equifax executives traded on inside knowledge" splits cleanly on the record: two individuals were convicted of exactly that — and the senior executives whose August sales drew the first suspicion were cleared by an independent committee and never charged. Both halves stay on this page at full strength.
Weigh the costly signals: the company paid up to $700 million, the largest breach settlement of its day, and still does not admit liability. The two people who profited privately paid with convictions. The 147 million people whose files were taken did not choose to be in the database, and cannot leave it.
The archive does not judge. The archive merely keeps the tape running.
evidence locker
PRIMARY RECORD — GOVERNMENT & COURT
U.S. House Committee on Oversight and Government Reform — "The Equifax Data Breach" majority staff report (Dec 2018) FACT — the patch timeline, the US-CERT notice, the intrusion, and the congressional findings.
oversight.house.gov/…/Equifax-Report.pdf
SEC — "Former Equifax Executive Charged With Insider Trading," Press Release 2018-40 (Mar 14, 2018) FACT — the SEC's charge against Jun Ying. (Live; may bot-block automated fetches.)
sec.gov/newsroom/press-releases/2018-40
PRESS & REFERENCE
THE SUBJECT'S OWN VOICE & THE DEFENSE ON THE RECORD
The standard. Everything above is sourced to a congressional report and hearing transcript, FTC and CFPB settlement announcements, SEC and DOJ filings on two criminal convictions, Equifax's own board committee findings and press releases, and named press. Facts are stated as facts. The company's negligence is stated as documented conduct; the two convictions are stated as convictions; and the executives whose stock sales first drew suspicion are stated as cleared, because an independent committee cleared them and no charge was ever brought. The company is distinguished from the individuals; the civil settlement is distinguished from a criminal finding; the defense — the clearance, the non-admission of liability, the remediation — is presented at full strength. No motive is asserted about any person. The burden of proof is on us, not the subject. If it couldn't survive a defamation challenge, it wouldn't be on this page.