• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Tech

Equifax’s Mega-Breach Was Made Possible by a Website Flaw It Could Have Fixed

By
David Meyer
David Meyer
Down Arrow Button Icon
By
David Meyer
David Meyer
Down Arrow Button Icon
September 14, 2017, 5:25 AM ET

Good website security is tough, but the consequences of bad website security can be far tougher. That appears to be one of the big lessons coming out the debacle surrounding Equifax’s mega-breach, which has “humbled” the credit-reporting giant.

On Wednesday, Equifax gave an update on its investigations of the breach, explaining that it had identified the culprit—a vulnerability on part of its U.S. website, specifically a flaw in the open-source Apache Struts framework it used to build its web applications.

This particular vulnerability, which carries the code “CVE-2017-5638,” was fixed back in early March, with patches becoming available then to everyone who uses Struts. Equifax said the breach occurred in the middle of May.

That means Equifax’s IT department had the means to fix the problem for a couple of months, but did not. The rest is history.

To be fair, as Ars Technica has pointed out, this was not an easy flaw to fix. It meant rebuilding all the web apps that people had already built using Struts, except this time using the updated version.

So at this point, it remains possible that Equifax’s development team might have been in the process of doing this when the breach hit.

But even if that were the case, they would have been too slow. It only took a few days after the bug was made public on March 6 for hackers to start attacking websites that relied on the framework. More than two months later, they scored their biggest hit.

Now, with more than 143 million people having lost their personal details, Equifax is facing questions from legislators and the public. So far, the answers aren’t proving comfortable.

About the Author
By David Meyer
LinkedIn icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.


Most Popular

placeholder alt text
Big Tech
The Chan Zuckerberg Initiative cut 70 jobs as the Meta CEO’s philanthropy goes all in on mission to 'cure or prevent all disease'
By Sydney LakeFebruary 1, 2026
2 days ago
placeholder alt text
Economy
'I just don't have a good feeling about this': Top economist Claudia Sahm says the economy quietly shifted and everyone's now looking at the wrong alarm
By Eleanor PringleJanuary 31, 2026
3 days ago
placeholder alt text
Future of Work
Ford CEO has 5,000 open mechanic jobs with up to 6-figure salaries from the shortage of manually skilled workers: 'We are in trouble in our country'
By Marco Quiroz-GutierrezJanuary 31, 2026
2 days ago
placeholder alt text
Success
U.S. Olympic gold medalist went from $200,000-a-year sponsorship at 20 years old to $12-an-hour internship by 30
By Orianna Rosa RoyleFebruary 1, 2026
1 day ago
placeholder alt text
Success
Ryan Serhant starts work at 4:30 a.m.—he says most people don’t achieve their dreams because ‘what they really want is just to be lazy’
By Preston ForeJanuary 31, 2026
3 days ago
placeholder alt text
Economy
Musk’s fantasy for a future where work is optional just got more real: U.K. minister calls for universal basic income to cushion AI-related job losses
By Sasha RogelbergFebruary 1, 2026
2 days ago

Latest in Tech

karp
AIMarkets
‘We are an n of 1’: Palantir hails ‘incredible’ earnings as stock rockets nearly 8% after hours
By Nick LichtenbergFebruary 2, 2026
2 hours ago
Man speaking with a blue background.
AIElon Musk
Elon Musk’s SpaceX buys xAI in stunning deal valued at $1.25 trillion ahead of looming IPO
By Amanda GerutFebruary 2, 2026
3 hours ago
altman
AIMarkets
Oracle said it was ‘highly confident in OpenAI’s ability to raise funds and meet its commitments.’ Cue the stock fall
By Eva RoytburgFebruary 2, 2026
3 hours ago
EnergyDevon Energy
Devon Energy CEO: ‘Stars align’ to acquire Coterra for nearly $26 billion as merger mania returns to the oilfield
By Jordan BlumFebruary 2, 2026
5 hours ago
schlicht
AIBots
Meet Matt Schlicht, the man behind AI’s latest Pandora’s box—a social network where AI agents talk to one another
By Nick LichtenbergFebruary 2, 2026
6 hours ago
Andy Jassy speaks onstage.
AILabor
If AI is roiling the job market, the data isn’t showing it, Yale Budget Lab report says, raising questions of ‘AI-washing’ to justify mass layoffs
By Sasha RogelbergFebruary 2, 2026
6 hours ago