Equifax Discovered Its Data Breach on July 29, 2017. Its CFO Sold Nearly $950,000 in Company Stock Three Days Later.

Share
Equifax Discovered Its Data Breach on July 29, 2017. Its CFO Sold Nearly $950,000 in Company Stock Three Days Later.
Photo by Kelly Sikkema / Unsplash

On July 29, 2017, an Equifax security engineer updated a network-monitoring certificate that had been allowed to expire ten months earlier, sat unnoticed for 19 months, and immediately watched suspicious traffic pouring out of a consumer-dispute database. The company would spend the next 40 days deciding when, and how, to tell the public.

Equifax is one of three companies in the United States that decides, on the public's behalf and without its consent, what its credit looks like. By the time it finished counting in 2018, the breach had exposed the Social Security numbers, birthdates, addresses, and in some cases driver's license and credit card numbers of 147.9 million Americans — data the company had never asked anyone's permission to collect in the first place.

A Patch That Sat Unused for 145 Days

The vulnerability, CVE-2017-5638, was a remote-code-execution flaw in the Apache Struts web framework, used by Equifax's online dispute portal. The Apache Software Foundation released a patch for it on March 7, 2017. The Department of Homeland Security notified Equifax, along with Experian and TransUnion, of the vulnerability the very next day, March 8. Equifax's internal security team emailed administrators on March 9 instructing them to apply the patch.

  • A scan Equifax ran on March 15, 2017 to confirm the patch had been applied failed to detect the still-vulnerable system.
  • Attackers gained access through the unpatched portal and moved through Equifax's network from mid-May through July 2017, according to the Government Accountability Office.
  • The device meant to inspect encrypted traffic on the affected application had been offline for 19 months because the digital certificate authorizing it to decrypt that traffic had expired and no one had renewed it — until July 29, 2017, when a security engineer finally did, and immediately found the intrusion already in progress.

Equifax took the dispute portal offline on July 30, 2017. It did not tell the public what it had found until September 7, 2017 — 40 days later.

Four Executives Sold Stock Six Days After the Company Found Out

Equifax detected the intrusion on the evening of July 29, 2017. Between July 28 and August 1, four senior officers — Chief Financial Officer John Gamble, business-unit presidents Joseph Loughran and Rodolfo Ploder, and investor-relations executive Douglas Brandberg — sought and received internal preclearance to sell company stock. Gamble sold shares worth roughly $946,000 on August 1. Combined, the four sold nearly $1.8 million in Equifax stock before the company told anyone outside a small internal circle what had happened.

A special committee of Equifax's board reviewed the trades that November and concluded none of the four executives knew about the breach when they sold — Gamble, the committee said, did not learn a security incident was under investigation until August 10, more than a week after his trade cleared.

A fifth Equifax employee did not get the benefit of that finding. Jun Ying, next in line to become chief information officer of a major Equifax business unit, pieced together from an internal request that the company had suffered a serious breach weeks before it went public. He exercised his stock options and sold the shares for proceeds of roughly $950,000, avoiding more than $117,000 in losses he would have taken had he waited for the public disclosure. The SEC charged him with insider trading in March 2018. He pleaded guilty and, in June 2019, was sentenced to four months in federal prison, a year of supervised release, a $55,000 fine, and $117,117.61 in restitution.

The Company's Own Recovery Site Sent Victims to a Fake One

When Equifax finally disclosed the breach on September 7, 2017, it directed consumers to a dedicated site, equifaxsecurity2017.com, and offered a year of free credit monitoring through its own product, TrustedID Premier.

  • TrustedID Premier's terms of service initially required enrollees to resolve any dispute through binding arbitration and to waive the right to join a class-action lawsuit — including, as written, claims arising from the breach itself. After public backlash, Equifax issued a statement days later clarifying the clause would not apply to breach-related claims.
  • Equifax's own official Twitter account linked to the wrong URL — securityequifax2017.com instead of equifaxsecurity2017.com — in at least eight separate tweets. The domain had already been registered by a security researcher, Nick Sweeting, specifically to demonstrate how easily a scammer could have done the same thing. Roughly 200,000 people were redirected to his site before Equifax noticed.

A Music Degree and 324 Expired Certificates

In the weeks after disclosure, Equifax's chief security officer, Susan Mauldin, and chief information officer, David Webb, both left the company, effective September 15, 2017. Mauldin held a bachelor's degree and a Master of Fine Arts in music composition from the University of Georgia; she had 14 years of security experience elsewhere in industry, but no degree specific to the field, a detail that drew widespread public attention once her LinkedIn profile surfaced.

The Government Accountability Office's 2018 review found the missing credentials were not the operative failure. Investigators identified an outdated internal notification list that meant the March patch instructions never reached everyone who needed them, a misconfiguration that let roughly 9,000 database queries by the attackers go undetected, and a company-wide pattern behind the expired certificate that triggered discovery: Equifax had let at least 324 of its digital certificates lapse across its network, 79 of them on systems monitoring business-critical domains.

The CEO Apologized to Congress and Kept His Pension

Chairman and CEO Richard Smith "retired" effective September 26, 2017, one week before he was scheduled to testify before Congress. He testified anyway, appearing before the House Energy and Commerce Committee on October 3, 2017, where he told lawmakers the breach was the result of "human error and technology failures" and said he was "deeply sorry" for what had happened.

As a condition of his retirement, Smith forfeited his 2017 bonus, worth more than $3 million. He kept a pension valued at roughly $18.4 million, on top of salary and vested equity — a package various outlets tallied at up to $90 million in total potential value.

The People Who Actually Got Punished

On July 22, 2019, Equifax reached a global settlement with the Federal Trade Commission, the Consumer Financial Protection Bureau, and 48 states, the District of Columbia, and Puerto Rico, worth up to $700 million. The deal included $175 million in penalties to the states, $100 million in civil penalties to the CFPB, and up to $425 million for a consumer restitution fund covering credit monitoring and out-of-pocket losses.

Consumers were told they could claim a cash payment of up to $125 instead of credit monitoring. The alternative-payment pool was capped at $31 million; once claims vastly outstripped it, the FTC publicly walked the number back and urged people to take the free monitoring instead, since the actual per-person cash payout would come to a small fraction of $125.

On February 10, 2020, then-Attorney General William Barr announced a nine-count federal indictment against four members of a unit of China's People's Liberation Army — Wu Zhiyong, Wang Qian, Xu Ke, and Liu Lei — for carrying out the intrusion, calling it "a deliberate and sweeping intrusion into the private information of the American people." None of the four has been arrested.

The Chinese military officers charged with carrying out the Equifax breach remain, as of this writing, at large and outside U.S. jurisdiction. The one person sentenced to prison over the Equifax breach was Jun Ying, for selling his own stock nine days before the public found out what he'd figured out on his own. Richard Smith did not go to prison. He kept the pension.


Filed from public reporting:

Read more

A Hand-Tightened Blind Flange and a Botched Shift Handover Killed 167 Men on Occidental Petroleum's Piper Alpha Platform in 22 Minutes. No One at the Company Was Ever Criminally Charged.

A Hand-Tightened Blind Flange and a Botched Shift Handover Killed 167 Men on Occidental Petroleum's Piper Alpha Platform in 22 Minutes. No One at the Company Was Ever Criminally Charged.

At around 10 p.m. on July 6, 1988, a pressure safety valve that had been pulled for maintenance that morning let gas condensate leak past a blind flange that had only been hand-tightened. Within 22 minutes, the Piper Alpha platform, 120 miles northeast of Aberdeen in the North

By The Complaints Department
Netflix Spent Six Years Telling Customers Love Is Sharing a Password. Once It Started Charging $7.99 a Month Per Shared Password Instead, Subscriber Growth Hit Its Best Year Since the Pandemic.

Netflix Spent Six Years Telling Customers Love Is Sharing a Password. Once It Started Charging $7.99 a Month Per Shared Password Instead, Subscriber Growth Hit Its Best Year Since the Pandemic.

On March 10, 2017, Netflix's official Twitter account posted four words that would follow the company around for the next six years: "Love is sharing a password." It was a promo tweet for a show called Love, but it was also, unmistakably, a policy statement — an

By The Complaints Department
New York Paused Congestion Pricing for 'Affordability' Weeks Before a 2024 Election, Then Relaunched It at a Lower Price Once Voting Was Over. A Year Later, Traffic Was Down 11 Percent and the Federal Government Was Still in Court Trying to Kill It.

New York Paused Congestion Pricing for 'Affordability' Weeks Before a 2024 Election, Then Relaunched It at a Lower Price Once Voting Was Over. A Year Later, Traffic Was Down 11 Percent and the Federal Government Was Still in Court Trying to Kill It.

On June 5, 2024, Governor Kathy Hochul stood before reporters and "indefinitely paused" New York's Central Business District Tolling Program, the long-planned congestion charge for driving into Manhattan below 60th Street. The launch was three weeks away. Hochul cited affordability concerns for working- and middle-

By The Complaints Department
Twitter Cut Off the Third-Party Apps That Built Its Developer Ecosystem in January 2023 With No Warning. One of Those Apps Coined the Word Tweet and Designed Twitter's Bird Logo Before Twitter Had Either.

Twitter Cut Off the Third-Party Apps That Built Its Developer Ecosystem in January 2023 With No Warning. One of Those Apps Coined the Word Tweet and Designed Twitter's Bird Logo Before Twitter Had Either.

On January 13, 2023, Twitter's API went dark for third-party client apps with no announcement and no explanation. Tweetbot, Twitterrific, Fenix, and others simply stopped working, all at once, for everyone. Developers spent days guessing whether it was a bug, an outage, or deliberate. Four days later,

By The Complaints Department