US credit reporting agency Equifax disclosed a data breach affecting around 143 million US consumers, a figure it later raised to about 147 million. Data on millions of people in the UK and Canada was also exposed.
What happened
- Attackers exploited a known vulnerability in the Apache Struts web framework, for which a patch had been released in March 2017.
- They accessed data between May and July 2017, including names, Social Security numbers, dates of birth, and addresses.
- The chief executive and other senior executives left the company within weeks.
- In 2019 Equifax agreed a settlement of at least $575m with the Federal Trade Commission and others, and the UK ICO fined its UK arm £500,000.
Why it mattered
Equifax became a textbook case of the consequences of slow patching, and it highlighted how much sensitive data is held by organisations that consumers do not deal with directly.
Lessons for organisations
Maintain an accurate asset inventory, patch critical internet-facing vulnerabilities quickly, and monitor for data leaving the network. Organisations should also minimise the personal data they hold.
Source: Federal Trade Commission
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.