The 2017 Equifax data breach was a significant cyber attack that compromised the personal information of approximately 147 million Americans (as well as individuals in the UK and Canada). Equifax, one of the three major U.S. credit reporting agencies, was hacked due to a security vulnerability in its web application framework, Apache Struts. This breach exposed sensitive personal data, including:

  • Social Security numbers

  • Names

  • Birth dates

  • Addresses

  • Driver's license numbers

  • In some cases, credit card numbers and dispute information

How the Breach Happened

The breach occurred because Equifax failed to patch a known security flaw in Apache Struts, which was publicly disclosed in March 2017. The hackers took advantage of the vulnerability to gain access to Equifax’s systems and stole sensitive data over a period of several months.

Placeholder
  • Add a short summary or a list of helpful resources here.