Timeline
Equifax: a breach, a delay and the case for a clear disclosure duty
Equifax discovered its breach in late July 2017 but did not disclose it publicly until 7 September, a delay that reshaped the debate over data-breach law.
Daniel Reyes
Senior Editor, American Computer Society
September 2017 · 7 min read

The Equifax breach exposed sensitive data on approximately 147 million Americans and became a defining test of how long companies can sit on knowledge of a breach before telling the people affected.
From intrusion to disclosure
Equifax, one of the three major US consumer credit reporting agencies, disclosed on 7 September 2017 that criminals had exploited a vulnerability in the Apache Struts web application framework to access company systems, exposing names, Social Security numbers, birth dates, addresses and in some cases driver's licence numbers of approximately 143 million US consumers, a figure later revised upward to roughly 147 million.
Equifax stated the intrusion occurred from mid-May through July 2017 and that it discovered the breach on 29 July 2017 — meaning roughly six weeks elapsed between discovery and public disclosure. The Apache Struts vulnerability Equifax had failed to patch, CVE-2017-5638, had a fix available since March 2017, months before the breach began.
Scrutiny intensified after it emerged that Equifax executives sold company shares in the days after the breach was discovered but before it was disclosed. The company's then-chief executive, Richard Smith, retired amid the fallout in late September 2017 and testified before Congress the following month.
“Consumers had no chance to protect themselves during the six weeks Equifax knew and they did not.”
The regulatory and financial aftermath
In July 2019 Equifax agreed to a settlement with the US Federal Trade Commission, the Consumer Financial Protection Bureau and 50 US states and territories worth up to $700 million, covering consumer compensation, credit monitoring and penalties — at the time among the largest data-breach settlements in US history.
The breach also renewed a long-running US policy debate over the absence of a single federal data-breach notification law; disclosure obligations in 2017 were governed by a patchwork of state statutes with varying deadlines.
Why the six-week gap mattered
Congressional testimony and subsequent investigations found the delay was used internally for forensic investigation and legal preparation, but consumers had no opportunity during that period to freeze credit files or monitor accounts for fraud arising from data they did not know had been exposed. The case became a central example cited by advocates of mandatory, time-bound breach notification requirements.
What the Society advises
The Society holds that timely, honest disclosure of a data breach to affected individuals and regulators is a professional and ethical obligation, not solely a legal or public-relations calculation.
- Patch known, disclosed vulnerabilities in internet-facing systems without unreasonable delay.
- Establish a breach-response plan with pre-agreed disclosure timelines before an incident occurs.
- Ensure legal and forensic review does not become a pretext for withholding notification from those affected.
- Support consistent, mandatory breach-notification standards rather than a fragmented state-by-state approach.
Join the professional body behind this work
ACS members receive our research first, free CPD and ethics modules every year, and a route to professional registration assessed by their peers.
Become a memberMore from ACS Insights
Optimus: a humanoid robot from prototype to production line
Four years from an AI Day slide to a converted Fremont assembly line — and still no commercial sale.
AnalysisGrok, Colossus and the compute arms race
xAI built a 100,000-GPU cluster in 122 days, doubled it, and merged twice. The externalities arrived with the electricity.
ArticleA national consortium to build trust in AI
ACS joins federal partners, universities and industry to strengthen assurance practice for high-impact AI systems.