Credit reporting agency Equifax Inc. agreed to pay at least $575 million, and potentially up to $700 million, to settle federal and state investigations into a 2017 data breach that exposed the personal information of approximately 147 million people, under a global settlement announced July 22, 2019, with the FTC, the Consumer Financial Protection Bureau, and all fifty states plus the District of Columbia and Puerto Rico.DOCUMENTED
At the time of its announcement, the settlement represented the largest data-breach settlement ever reached in the United States, reflecting both the scale of the breach and the extent of the personal financial information exposed.DOCUMENTED
- Equifax agreed to pay at least $575 million, rising to as much as $700 million depending on how many affected consumers filed claims.
- The breach exposed Social Security numbers, birth dates, addresses, and in some cases driver's license numbers for approximately 147 million people.
- The breach resulted from Equifax's failure to patch a known software vulnerability in an open-source web application framework for months after the flaw was publicly disclosed.
- The settlement included $300 million for a fund providing credit monitoring and identity-restoration services, with an additional $125 million available if the first fund proved insufficient.
- Equifax also agreed to spend a minimum of $1 billion over five years improving its data security practices.
The vulnerability that went unpatched
According to the FTC's complaint, the breach originated with a known vulnerability in Apache Struts, an open-source web application framework used by Equifax to run part of its online dispute portal. The vulnerability had been publicly disclosed and a patch made available months before hackers actually exploited it to gain access to Equifax's systems, a delay the FTC's complaint characterized as a failure of the company's data-security practices given the sensitivity of the information at risk.DOCUMENTED
Once inside Equifax's network, attackers were able to access and exfiltrate an enormous volume of highly sensitive consumer data over a period of months before the breach was discovered and disclosed, ultimately affecting approximately 147 million people — roughly 44 percent of the U.S. population at the time, and a substantial share of everyone who has ever had a credit history in the United States.DOCUMENTED
What was exposed
The information compromised in the breach included some of the most sensitive categories of personal data used across the U.S. financial system: Social Security numbers, birth dates, and home addresses for the large majority of affected consumers, along with driver's license numbers for a substantial subset. Because Equifax is one of the three major nationwide credit reporting agencies, the exposed data set was uniquely comprehensive, covering financial identity information for consumers regardless of whether they had ever directly done business with the company themselves.DOCUMENTED
The settlement's structure
The core of the settlement's consumer-facing relief was a $300 million fund established to provide affected consumers with free credit monitoring services and to reimburse those who had already purchased credit-monitoring or identity-protection services on their own following the breach. The settlement included a mechanism to add an additional $125 million to that fund if the initial amount proved insufficient to cover all eligible claims, up to a combined cap of $425 million in direct consumer relief.DOCUMENTED
Beyond direct consumer compensation, Equifax agreed to pay $175 million to the fifty states, the District of Columbia, and Puerto Rico, and $100 million in civil penalties to the Consumer Financial Protection Bureau. The settlement separately required Equifax to spend a minimum of $1 billion over the following five years on strengthening its data security infrastructure and practices, a figure regulators presented as reflecting the scale of remediation needed given the sensitivity of the credit-reporting data the company handles.DOCUMENTED
Why credit bureaus draw particular scrutiny
"Equifax failed to take basic steps that may have prevented the breach that affected approximately 147 million consumers," the FTC stated in its announcement, emphasizing that credit reporting agencies occupy a uniquely sensitive position in the consumer financial system: unlike a retailer or social media platform, whose data exposure primarily affects its own direct customers, a credit bureau breach exposes financial identity data for consumers who never chose to do business with the company at all, since credit bureaus compile data automatically as part of the broader credit-reporting system regardless of individual consumer consent.DOCUMENTED
A benchmark for future breach cases
At the time, the Equifax settlement's combined value, potentially reaching $700 million, was without precedent for a data-breach case and was explicitly framed by regulators as intended to send a message to other companies handling large volumes of sensitive consumer financial data about the consequences of failing to patch known vulnerabilities in a timely manner. The case has since become a frequently cited benchmark in subsequent data-security enforcement actions and in corporate risk assessments regarding the cost of delayed vulnerability patching across industries far beyond credit reporting.REVIEWED
The breach's aftermath also reshaped how consumers interact with the credit-reporting system more broadly: in the years following the settlement, all three major credit bureaus, including Equifax itself, began offering free credit-freeze services nationwide, partly in response to public pressure following the breach and subsequent federal legislation making credit freezes free by law. For the 147 million people whose data was exposed, however, the practical risk of identity theft tied to permanently compromised Social Security numbers persists indefinitely, since unlike a compromised password or credit card number, a Social Security number cannot simply be reissued once exposed.REVIEWED
Cybersecurity researchers who reviewed the incident afterward frequently point to the months-long gap between the Apache Struts vulnerability's public disclosure and its eventual exploitation as the case's most instructive detail: unlike a so-called zero-day vulnerability, for which no defense yet exists at the time of an attack, this flaw had a known, available patch that simply was not applied in time across Equifax's relevant systems.REVIEWED
The settlement's structure, splitting funds between direct consumer compensation, state penalties, and a mandated minimum security-spending commitment, has since served as a template other regulators have referenced when negotiating breach settlements with companies handling comparably sensitive categories of consumer financial data, even as the sheer scale of Equifax's exposure — nearly half the U.S. adult population — remains largely unmatched by any subsequent breach settlement.REVIEWED
Sources behind this report
Have documents relevant to this story? Reach us through our tips channel.