RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Incident

Incident / From the archive · 7 September 2017 event · prepared 16 September 2026

Equifax left a known web-framework flaw unpatched for months

A federal audit and an FTC settlement trace the 2017 breach to a missed patch notice and an expired certificate.

Visual for this record: Equifax left a known web-framework flaw unpatched for months
Visual published by ftc.gov, shown for identification of the record. Credit: ftc.gov · source page ↗ Rights: owner-review-pending.

What happened

On 7 September 2017, Equifax disclosed that attackers had accessed personal data belonging to an estimated 143 million US consumers, a figure later revised upward. According to the company's own disclosure filed with the Securities and Exchange Commission, the intrusion ran from mid-May through 29 July 2017 and exposed names, Social Security numbers, birth dates, addresses and, for some consumers, driver's licence numbers and credit card details. A review by the Government Accountability Office traces the root cause to Apache Struts, a web-application framework: a critical flaw in it was disclosed and patched in March 2017, roughly two months before attackers began extracting data through Equifax's online dispute portal, which still ran the vulnerable version.

The GAO review and the Federal Trade Commission's subsequent settlement both describe how the failure persisted: an internal notice about the flaw did not reach the employee responsible for the dispute portal, and a follow-up vulnerability scan was not configured to find the affected system. A second, separate failure then delayed detection for months: an expired network-monitoring certificate meant Equifax could not inspect encrypted traffic on the affected server, so the certificate had to be replaced before unusual activity became visible.

Confidence and limits

These details come from a congressionally requested audit that reviewed Equifax's own investigation and interviewed federal customer agencies, and from a federal enforcement settlement, so the patch failure and certificate lapse are well corroborated. Neither document independently re-verified Equifax's internal logs; both state they relied on the company's own reconstruction. The final consumer count, revised twice, should be read as Equifax's best estimate from incomplete records rather than an exact figure.

Why it mattered

Equifax held identity data on most of the US adult population without those people choosing to be its customer, a poor fit for the usual advice to change a password. The case became a reference point for patch management because the failure was not a missing fix, one existed within days of disclosure, but a gap between a security team's notice and the owner responsible for applying it. The settlement's board-oversight requirement shaped how regulators since have framed adequate data-security governance.

Defensive takeaway

Confirm that your patch process tracks acknowledgement down to the individual system owner rather than a mass notice, and check whether any device inspecting your encrypted traffic for threats has a certificate that is due to expire or has already lapsed.

  • Do you have a current, verified inventory of every public-facing system running a specific open-source framework, so a critical advisory can be matched to an owner within hours?
  • Would a critical-patch notice sent to a distribution list definitely reach the specific engineer responsible for the affected system?
  • Are any of your network-security appliances relying on a certificate that has expired or is close to expiring?

The Equifax breach is often remembered for its scale, but the more transferable lesson is procedural: a known vulnerability with an available patch sat exposed for months because two ordinary failures, a missed notification and a misconfigured scan, went unnoticed until an expired certificate was replaced in the course of routine maintenance.

Defensive takeaway

Confirm your patch process tracks acknowledgement to the individual system owner rather than a mass notice, and check whether any device inspecting encrypted traffic for threats has a certificate that is expiring or already expired.

A congressional audit and a federal enforcement settlement corroborate the patch-notification failure and the certificate lapse; both rely on Equifax's own forensic reconstruction rather than independent verification of internal logs, and the final consumer count was revised more than once.

Sources & reading trail

Data Protection: Actions Taken by Equifax and Federal Agencies in Response to the 2017 Breach (GAO-18-559) ↗

Traces the breach to the unpatched Apache Struts vulnerability, the missed internal patch notice, the misconfigured scan, and the expired certificate that delayed detection.

government-primary · Source published: 30 August 2018 · Retrieved: 16 September 2026

Equifax to Pay $575 Million as Part of Settlement with FTC, CFPB, and States Related to 2017 Data Breach ↗

Confirms the settlement amount, the approximately 147 million affected consumers, and the required security governance reforms.

court-or-regulator-primary · Source published: 22 July 2019 · Retrieved: 16 September 2026

Equifax Announces Cybersecurity Incident Involving Consumer Information ↗

Equifax's own initial disclosure of the discovery date, the window of unauthorized access, and the types of data exposed.

company-primary · Source published: 7 September 2017 · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.