Equifax Discovered Its Data Breach on July 29, 2017. Its CFO Sold Nearly $950,000 in Company Stock Three Days Later.
On July 29, 2017, an Equifax security engineer updated a network-monitoring certificate that had been allowed to expire ten months earlier, sat unnoticed for 19 months, and immediately watched suspicious traffic pouring out of a consumer-dispute database. The company would spend the next 40 days deciding when, and how, to tell the public.
Equifax is one of three companies in the United States that decides, on the public's behalf and without its consent, what its credit looks like. By the time it finished counting in 2018, the breach had exposed the Social Security numbers, birthdates, addresses, and in some cases driver's license and credit card numbers of 147.9 million Americans — data the company had never asked anyone's permission to collect in the first place.
A Patch That Sat Unused for 145 Days
The vulnerability, CVE-2017-5638, was a remote-code-execution flaw in the Apache Struts web framework, used by Equifax's online dispute portal. The Apache Software Foundation released a patch for it on March 7, 2017. The Department of Homeland Security notified Equifax, along with Experian and TransUnion, of the vulnerability the very next day, March 8. Equifax's internal security team emailed administrators on March 9 instructing them to apply the patch.
- A scan Equifax ran on March 15, 2017 to confirm the patch had been applied failed to detect the still-vulnerable system.
- Attackers gained access through the unpatched portal and moved through Equifax's network from mid-May through July 2017, according to the Government Accountability Office.
- The device meant to inspect encrypted traffic on the affected application had been offline for 19 months because the digital certificate authorizing it to decrypt that traffic had expired and no one had renewed it — until July 29, 2017, when a security engineer finally did, and immediately found the intrusion already in progress.
Equifax took the dispute portal offline on July 30, 2017. It did not tell the public what it had found until September 7, 2017 — 40 days later.
Four Executives Sold Stock Six Days After the Company Found Out
Equifax detected the intrusion on the evening of July 29, 2017. Between July 28 and August 1, four senior officers — Chief Financial Officer John Gamble, business-unit presidents Joseph Loughran and Rodolfo Ploder, and investor-relations executive Douglas Brandberg — sought and received internal preclearance to sell company stock. Gamble sold shares worth roughly $946,000 on August 1. Combined, the four sold nearly $1.8 million in Equifax stock before the company told anyone outside a small internal circle what had happened.
A special committee of Equifax's board reviewed the trades that November and concluded none of the four executives knew about the breach when they sold — Gamble, the committee said, did not learn a security incident was under investigation until August 10, more than a week after his trade cleared.
A fifth Equifax employee did not get the benefit of that finding. Jun Ying, next in line to become chief information officer of a major Equifax business unit, pieced together from an internal request that the company had suffered a serious breach weeks before it went public. He exercised his stock options and sold the shares for proceeds of roughly $950,000, avoiding more than $117,000 in losses he would have taken had he waited for the public disclosure. The SEC charged him with insider trading in March 2018. He pleaded guilty and, in June 2019, was sentenced to four months in federal prison, a year of supervised release, a $55,000 fine, and $117,117.61 in restitution.
The Company's Own Recovery Site Sent Victims to a Fake One
When Equifax finally disclosed the breach on September 7, 2017, it directed consumers to a dedicated site, equifaxsecurity2017.com, and offered a year of free credit monitoring through its own product, TrustedID Premier.
- TrustedID Premier's terms of service initially required enrollees to resolve any dispute through binding arbitration and to waive the right to join a class-action lawsuit — including, as written, claims arising from the breach itself. After public backlash, Equifax issued a statement days later clarifying the clause would not apply to breach-related claims.
- Equifax's own official Twitter account linked to the wrong URL — securityequifax2017.com instead of equifaxsecurity2017.com — in at least eight separate tweets. The domain had already been registered by a security researcher, Nick Sweeting, specifically to demonstrate how easily a scammer could have done the same thing. Roughly 200,000 people were redirected to his site before Equifax noticed.
A Music Degree and 324 Expired Certificates
In the weeks after disclosure, Equifax's chief security officer, Susan Mauldin, and chief information officer, David Webb, both left the company, effective September 15, 2017. Mauldin held a bachelor's degree and a Master of Fine Arts in music composition from the University of Georgia; she had 14 years of security experience elsewhere in industry, but no degree specific to the field, a detail that drew widespread public attention once her LinkedIn profile surfaced.
The Government Accountability Office's 2018 review found the missing credentials were not the operative failure. Investigators identified an outdated internal notification list that meant the March patch instructions never reached everyone who needed them, a misconfiguration that let roughly 9,000 database queries by the attackers go undetected, and a company-wide pattern behind the expired certificate that triggered discovery: Equifax had let at least 324 of its digital certificates lapse across its network, 79 of them on systems monitoring business-critical domains.
The CEO Apologized to Congress and Kept His Pension
Chairman and CEO Richard Smith "retired" effective September 26, 2017, one week before he was scheduled to testify before Congress. He testified anyway, appearing before the House Energy and Commerce Committee on October 3, 2017, where he told lawmakers the breach was the result of "human error and technology failures" and said he was "deeply sorry" for what had happened.
As a condition of his retirement, Smith forfeited his 2017 bonus, worth more than $3 million. He kept a pension valued at roughly $18.4 million, on top of salary and vested equity — a package various outlets tallied at up to $90 million in total potential value.
The People Who Actually Got Punished
On July 22, 2019, Equifax reached a global settlement with the Federal Trade Commission, the Consumer Financial Protection Bureau, and 48 states, the District of Columbia, and Puerto Rico, worth up to $700 million. The deal included $175 million in penalties to the states, $100 million in civil penalties to the CFPB, and up to $425 million for a consumer restitution fund covering credit monitoring and out-of-pocket losses.
Consumers were told they could claim a cash payment of up to $125 instead of credit monitoring. The alternative-payment pool was capped at $31 million; once claims vastly outstripped it, the FTC publicly walked the number back and urged people to take the free monitoring instead, since the actual per-person cash payout would come to a small fraction of $125.
On February 10, 2020, then-Attorney General William Barr announced a nine-count federal indictment against four members of a unit of China's People's Liberation Army — Wu Zhiyong, Wang Qian, Xu Ke, and Liu Lei — for carrying out the intrusion, calling it "a deliberate and sweeping intrusion into the private information of the American people." None of the four has been arrested.
The Chinese military officers charged with carrying out the Equifax breach remain, as of this writing, at large and outside U.S. jurisdiction. The one person sentenced to prison over the Equifax breach was Jun Ying, for selling his own stock nine days before the public found out what he'd figured out on his own. Richard Smith did not go to prison. He kept the pension.
Filed from public reporting:
- The Apache Software Foundation — "Media Alert: The Apache Software Foundation Confirms Equifax Data Breach Due to Failure to Install Patches"
- U.S. Government Accountability Office — "Data Protection: Actions Taken by Equifax and Federal Agencies in Response to the 2017 Breach" (GAO-18-559)
- House Committee on Oversight and Government Reform — "The Equifax Data Breach" (Majority Staff Report, December 2018)
- U.S. Securities and Exchange Commission — "Former Equifax Executive Charged With Insider Trading"
- U.S. Department of Justice — "Attorney General William P. Barr Announces Indictment of Four Members of China's Military for Hacking into Equifax"
- Federal Trade Commission — "Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach"
- Equifax Inc. — "Equifax Board Releases Findings of Special Committee Regarding Stock Sale by Executives"
- CNBC — "Equifax cyberattack: three executives sold shares worth nearly $2 million days after data breach"
- The Atlanta Journal-Constitution — "Former Equifax exec gets 4 months in federal prison for insider trading"
- NPR — "Equifax CEO Richard Smith Resigns After Backlash Over Massive Data Breach"
- The Hill — "Errant Equifax tweet sends breach victims to site flagged for phishing"
- The Washington Post — "Equifax's security chief had some big problems. Being a music major wasn't one of them."