← Incident database

equifax-2017 · Disclosed 2017-09-07

Equifax: unpatched Apache Struts

A known Apache Struts vulnerability in the online dispute portal enabled theft of personal information. Patch instructions needed verification of actual deployment.

Known vulnerabilityCVE-2017-5638

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    CVE-2017-5638 in Apache Struts was the entry vector.

    [s1]Attack vector
  • Reported fact

    The organization had been notified, but the affected portal remained unpatched.

    [s2]GAO-18-559, p. 15: Identification

Timeline

  1. Suspicious network traffic detected. [s1]

  2. Breach disclosed. [s1]

Reported response

  • Reported fact

    The affected web application was taken offline for investigation and mitigation.

    [s1]本文 / Main text

Evidence relevant to prevention

Patch available beforehand

The vulnerability was known beforehand. Track patch notification through verification of the running version.

Editorial assessment; not a determination of liability. [s1][s2]

Unknowns and AI involvement

AI involvementUnknown

The cited primary sources do not establish AI involvement. This does not establish that AI was absent.

This summary cannot assess every asset or individual decision at the time.

Sources

  1. [s1] Equifax · Primary source

    Equifax Releases Details on Cybersecurity Incident ↗

    Published 2017-09-15 · Reviewed 2026-10-02

  2. [s2] U.S. GAO · Primary source

    Data Protection: Actions Taken in Response to the 2017 Breach ↗

    Published 2018-08-30 · Reviewed 2026-10-02