• Home
  • News
  • Fortune 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechEquifax

Thousands of Companies Are Still Downloading the Vulnerability That Wrecked Equifax

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
May 7, 2018, 9:00 AM ET

When the news emerged that Equifax had succumbed to a colossal data breach from mid-May through July of last year, consumers were livid—in part because the ransacking was entirely preventable. Hackers stole 148 million people’s names, Social Security numbers, birthdates, home addresses, and more sensitive information, as of the major credit bureau’s last count in March, and worse yet, it happened two months after software fixes for the vulnerabilities at fault had been made available.

In the year since, thousands of companies have continued to introduce the same security holes into their computer networks. As many as 10,801 organizations—including 57% of the Fortune Global 100—have downloaded known-to-be-vulnerable versions of Apache Struts, the popular, open source software package that attackers targeted to loot Equifax, from March 2017 through February 2018, according to data from Sonatype, a Goldman Sachs-backed cybersecurity startup that tracks code pulled by software developers.

The Apache Software Foundation released patched versions of the software employed by Equifax on March 7, 2017 as well as six other subsequent times throughout the year. But despite the availability of repaired code, businesses continue to download broken copies of Struts—a pervasive, app-building framework that helps power the transactional backends of many businesses—that are potentially susceptible to remote code execution, enabling an attacker to hijack a computer system from afar.

Sonatype did not identify specific companies that had downloaded flawed software. But of that set of 10,801 Struts-embrittled organizations, seven of the businesses were Fortune Global 100 tech companies, eight were Fortune Global 100 automakers, and 15 were Fortune Global 100 financial services or insurance firms, Sonatype researchers told Fortune.

A catastrophic hack didn’t change habits

Troublingly, the fallout from Equifax has not seemed to dissuade corporations from pulling unsafe code into their networks. As many as 8,780 organizations have continued to download known, vulnerable versions of the Struts software since Equifax’s breach disclosure on September 7, 2017, per Sonatype’s data. In other words, only about 1 in 5 businesses learned from Equifax’s debacle and stopped downloading faulty components once the heist of the credit bureau became publicly known.

The extent to which the corporate world has disregarded Equifax’s breach is startling. As many as 3,049 organizations have downloaded the exact same vulnerabilities that hackers exploited to break into Equifax—that is, the same holes contained in Struts versions 2.2.3 to 2.2.3.31 and 2.5 to 2.5.10, referenced in the U.S. government’s national vulnerability database under CVE-2017-5638, for the technically savvy—since the credit bureau’s breach disclosure, Sonatype researchers said.

To use an analogy, this is like completely ignoring an airbag recall and hoping not to get paralyzed in a collision—except worse because, in this scenario, malicious entities are actively trying to total other vehicles, including, potentially, yours.

“Downloading vulnerable versions of Struts is a symptom of a broader hygiene issue,” says Wayne Jackson, Sonatype’s CEO. “The problem is that these organizations don’t care enough to exert control, or don’t have infrastructure in place to know what’s being used.”

Sonatype was able to collect the data it shared with Fortune, Jackson explains, because it maintains a code repository, Maven Central, relied upon by many software developers as they build applications. When requests for code components come in, Sonatype is able to conduct reverse lookups on the requesters’ IP addresses, and thereby determine from which organizations they originated.

The failure to patch outdated software goes extends far beyond Struts. “We’ve probably got 10 million components that have defect associations,” Jackson says, referring to the output of other open source programming projects. “It’s not a problem that’s unique to Struts.” But Struts, he adds, is “a household name that should have gotten enough attention for people to change their behaviors.”

“Just because you create patches doesn’t mean customers will apply them,” says Joshua Corman, chief security officer at PTC, a Boston-based software shop, and cofounder of I Am the Cavalry, a grassroots organization focused on cybersecurity advocacy. “It takes a long time to fix this stuff at scale, but I’m worried they’re not trying rather than just being slow.”

Why companies don’t patch

Updating Struts tends to present a greater challenge for companies than applying other software fixes, such as simple Microsoft Windows updates. Because Struts libraries are often bundled with disparate web applications, fixing the issue requires, among other things: knowing which applications use these components; updating so-called build scripts so they fetch the latest versions of the software; rebuilding the applications; and running quality assurance tests to make sure the mended applications work as intended.

It’s not nearly as straightforward as download and reboot. And yet the problem demands swift remediation.

“You can’t sit around and say, well, it takes six months so we’re doing the best we can,” says Corman, who formerly served as chief technology officer of Sonatype until he left in March 2016. “The mean time to exploit is days.”

To be sure, it is possible that developers—and their automated, code-pulling software development scripts—are downloading faulty versions of Struts, yet not using them in any final product. It’s also possible that programmers are fixing the code themselves before deploying applications. It’s even possible that some organizations are relying on other security tools, like web application firewalls, to filter out possible attacks aimed at the flawed software.

Occam’s Razor suggests, however, that most organizations are simply failing to adhere to the most basic tenets of IT hygiene: Patch—promptly.

“I would expect, especially given the rage around Equifax, people would be finding ways to increase response time to remediate bugs in projects they rely upon,” Corman says.

Given Sonatype’s findings, apparently that’s not the case.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

MagazineFood and drink
A Chinese ice cream chain, powered by super-cheap cones, now has more outlets than McDonald’s
By Theodora YuDecember 3, 2025
52 minutes ago
InnovationBrainstorm Design
Video games can teach designers deeper lessons than ‘high score streaks’ and gamification
By Angelica AngDecember 3, 2025
4 hours ago
LawInternet
A Supreme Court decision could put your internet access at risk. Here’s who could be affected
By Dave Lozo and Morning BrewDecember 2, 2025
13 hours ago
AITikTok
China’s ByteDance could be forced to sell TikTok U.S., but its quiet lead in AI will help it survive—and maybe even thrive
By Nicholas GordonDecember 2, 2025
14 hours ago
United Nations
AIUnited Nations
UN warns about AI becoming another ‘Great Divergence’ between rich and poor countries like the Industrial Revolution
By Elaine Kurtenbach and The Associated PressDecember 2, 2025
15 hours ago
Anthropic cofounder and CEO Dario Amodei
AIEye on AI
How Anthropic’s safety first approach won over big business—and how its own engineers are using its Claude AI
By Jeremy KahnDecember 2, 2025
15 hours ago

Most Popular

placeholder alt text
Economy
Ford workers told their CEO 'none of the young people want to work here.' So Jim Farley took a page out of the founder's playbook
By Sasha RogelbergNovember 28, 2025
5 days ago
placeholder alt text
Success
Warren Buffett used to give his family $10,000 each at Christmas—but when he saw how fast they were spending it, he started buying them shares instead
By Eleanor PringleDecember 2, 2025
24 hours ago
placeholder alt text
Economy
Elon Musk says he warned Trump against tariffs, which U.S. manufacturers blame for a turn to more offshoring and diminishing American factory jobs
By Sasha RogelbergDecember 2, 2025
18 hours ago
placeholder alt text
North America
Jeff Bezos and Lauren Sánchez Bezos commit $102.5 million to organizations combating homelessness across the U.S.: ‘This is just the beginning’
By Sydney LakeDecember 2, 2025
19 hours ago
placeholder alt text
C-Suite
MacKenzie Scott's $19 billion donations have turned philanthropy on its head—why her style of giving actually works
By Sydney LakeDecember 2, 2025
1 day ago
placeholder alt text
North America
Anonymous $50 million donation helps cover the next 50 years of tuition for medical lab science students at University of Washington
By The Associated PressDecember 2, 2025
21 hours ago
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.