Equifax (Sept 2017): One Unpatched Apache Struts Server, 147 Million Records
Retrospective: this article looks back at events from September 2017, written in 2026 with the benefit of hindsight.
In September 2017, Equifax disclosed that attackers had stolen personal data on about 147 million people, including Social Security numbers, birth dates and addresses. It became one of the most consequential data breaches in history.
How it happened
In March 2017, a critical vulnerability in Apache Struts, a web application framework, was disclosed along with a patch. Equifax used Struts in a public-facing dispute portal. The system was not patched. Attackers exploited it in May and moved through the network for about 76 days.
Investigations by the US Government Accountability Office and a House committee found several compounding failures:
- An internal patching notice did not reach the team that owned the system.
- A vulnerability scan failed to detect the flaw.
- An expired certificate on a network traffic inspection device meant encrypted data leaving the network was not inspected for months. When the certificate was renewed, the suspicious traffic was spotted almost immediately.
- Attackers found credentials stored in plain text that helped them reach more databases.
Consequences
Equifax's CEO, CIO and CSO left the company. The company later agreed to a settlement with US regulators and states that could reach about $700 million.
Lessons for cloud-hosted applications
- Asset ownership matters. Patches are useless if no one knows who owns the system.
- Internet-facing applications need the fastest patch cycle you have.
- Monitoring tools fail silently. Track the health of your security controls, not just their alerts.
- Secrets in plain text multiply the damage of any initial compromise.
Equifax remains a reference case for executive accountability and for how many small process failures add up to a catastrophe.