• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Jamie Dimon runs JPMorgan’s 300,000 employees—but says it beats rivals by fighting in Navy SEAL-sized teams

2

Former CIA official found with $40 million in gold bars for 'work-related expenses' reaches tentative plea deal 

3

The trade deficit with Canada that's upset Trump so much is due to crude the U.S. buys at a discount for the Midwest. 'It’s the only oil they can use'

1

Jamie Dimon runs JPMorgan’s 300,000 employees—but says it beats rivals by fighting in Navy SEAL-sized teams

2

Former CIA official found with $40 million in gold bars for 'work-related expenses' reaches tentative plea deal 

3

The trade deficit with Canada that's upset Trump so much is due to crude the U.S. buys at a discount for the Midwest. 'It’s the only oil they can use'
TechEquifax

Equifax Underestimated by 2.5 Million the Number of Potential Breach Victims

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
October 2, 2017, 6:14 PM ET
Google source logo
Add Fortune on Google for similar content.

Equifax has revised its estimate for the number of people potentially affected by its recent massive data breach to a total of 145.5 million people, 2.5 million more than it initially reported.

One of three main credit reporting agencies in the U.S. next to Experian and TransUnion, Equifax (EFX) stores a trove of highly sensitive personal and financial details about consumers. From mid-May through July, an as yet unidentified hacker group gained access to a large swathe of this data—including names, birthdates, street addresses, credit card numbers, and Social Security numbers—the company disclosed last month.

Equifax released the new estimate on Monday, a day after Mandiant, the computer forensics division of the cybersecurity firm FireEye (FEYE) that Equifax hired, completed its full review of the damage. Despite the higher figure, Equifax said that Mandiant “did not identify any evidence of additional or new attacker activity or any access to new databases or tables.”

Equifax said Mandiant also found no evidence of unauthorized activity on databases located outside of the United States.

Get Data Sheet, Fortune’s technology newsletter

“I want to apologize again to all impacted consumers,” Paulino do Rego Barros, Jr., Equifax’s newly appointed interim CEO, said in a statement. “As this important phase of our work is now completed, we continue to take numerous steps to review and enhance our cybersecurity practices. We also continue to work closely with our internal team and outside advisors to implement and accelerate long-term security improvements.”

Equifax said that while it initially warned that data on about 100,000 Canadians may have been exposed, it has now revised that number down to 8,000 potential Canadian victims. The company said it would notify them through the mail.

Read more: “You Should Have Control Over Your Data—Not Sloppy Companies Like Equifax” by Elizabeth Warren

Equifax said it was still determining the extent of the breach for U.K. consumers.

In the weeks since Sept. 7, when Equifax first disclosed the compromise, a number of key leaders have left the company. Former CEO Richard Smith retired (banking as much as a $90 million payday), as did its chief information officer and chief security officer.

Equifax’s board said it is investigating other members of its executive team, including its chief financial officer and general counsel, for selling stock after the breach’s discovery, but before its public disclosure. A number of lawsuits have been filed against the company for allegedly mishandling people’s data.

Equifax has recommended that consumers enter some identifying details into a website it set up in the aftermath of the hack to determine whether they were affected. The company said it would update the database with the names of the additional millions of potentially affected consumers by Oct. 8.

Security pros have recommended that victims implement a credit freeze, which locks down credit records with a special PIN.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech


Most Popular

Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • TikTok icon
  • YouTube icon

    Latest in Tech


    Most Popular

    © 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
    FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.