• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military

2

'We are rapidly running out of time': Watchdog sounds Social Security alarm after 22% cut confirmed for 2032

3

Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there

1

Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military

2

'We are rapidly running out of time': Watchdog sounds Social Security alarm after 22% cut confirmed for 2032

3

Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there
Tech

Equifax’s Mega-Breach Was Made Possible by a Website Flaw It Could Have Fixed

By
David Meyer
David Meyer
Down Arrow Button Icon
By
David Meyer
David Meyer
Down Arrow Button Icon
September 14, 2017, 5:25 AM ET

Good website security is tough, but the consequences of bad website security can be far tougher. That appears to be one of the big lessons coming out the debacle surrounding Equifax’s mega-breach, which has “humbled” the credit-reporting giant.

On Wednesday, Equifax gave an update on its investigations of the breach, explaining that it had identified the culprit—a vulnerability on part of its U.S. website, specifically a flaw in the open-source Apache Struts framework it used to build its web applications.

This particular vulnerability, which carries the code “CVE-2017-5638,” was fixed back in early March, with patches becoming available then to everyone who uses Struts. Equifax said the breach occurred in the middle of May.

That means Equifax’s IT department had the means to fix the problem for a couple of months, but did not. The rest is history.

To be fair, as Ars Technica has pointed out, this was not an easy flaw to fix. It meant rebuilding all the web apps that people had already built using Struts, except this time using the updated version.

So at this point, it remains possible that Equifax’s development team might have been in the process of doing this when the breach hit.

But even if that were the case, they would have been too slow. It only took a few days after the bug was made public on March 6 for hackers to start attacking websites that relied on the framework. More than two months later, they scored their biggest hit.

Now, with more than 143 million people having lost their personal details, Equifax is facing questions from legislators and the public. So far, the answers aren’t proving comfortable.

About the Author
By David Meyer
LinkedIn icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Geoffrey von Maltzahn and Kimberly Powell on stage at Fortune Brainstorm Tech
AITerm Sheet
AI drug discovery leaders warn U.S. health funding cuts risk falling behind global rivals
By Lily Mae LazarusJune 10, 2026
41 minutes ago
Kevin O'Leary wears a silver and black suit with a chain of basketball cards around his neck.
AIData centers
From the Trump administration to Kevin O’Leary, there’s a new narrative that China is to blame for plummeting data center popularity
By Sasha RogelbergJune 10, 2026
2 hours ago
JB Straubel, co-founder of Tesla and founder and CEO of Redwood Materials, speaking at Fortune Brainstorm Tech 2026 in Aspen, Colorado. (Photo: Michael Faas/Fortune)
NewslettersFortune Tech
Why China is outpacing the U.S. power grid
By Andrew NuscaJune 10, 2026
3 hours ago
A $7 billion horse race: Goldman Sachs and Morgan Stanley battle for ‘lead left’ position ahead of OpenAI and Anthropic IPOs
Startups & VentureFinance
A $7 billion horse race: Goldman Sachs and Morgan Stanley battle for ‘lead left’ position ahead of OpenAI and Anthropic IPOs
By Shawn TullyJune 10, 2026
4 hours ago
Visa’s CFO downplays the importance of stablecoin and agentic commerce to the U.S. payments giant—at least in the short term
Bankingdigital and mobile payments
Visa’s CFO downplays the importance of stablecoin and agentic commerce to the U.S. payments giant—at least in the short term
By Angelica AngJune 10, 2026
4 hours ago
Man in a white shirt and jacket.
InnovationBrainstorm Tech
Marc Lore’s robots make 500 burrito bowls an hour. A human can make 45
By Amanda GerutJune 9, 2026
11 hours ago

Most Popular

Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military
Asia
Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military
By Kate O'Keeffe and BloombergJune 8, 2026
2 days ago
'We are rapidly running out of time': Watchdog sounds Social Security alarm after 22% cut confirmed for 2032
Economy
'We are rapidly running out of time': Watchdog sounds Social Security alarm after 22% cut confirmed for 2032
By Nick LichtenbergJune 9, 2026
19 hours ago
Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there
Success
Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there
By Preston ForeJune 8, 2026
2 days ago
Current price of oil as of June 9, 2026
Personal Finance
Current price of oil as of June 9, 2026
By Joseph HostetlerJune 9, 2026
22 hours ago
Trump, who has repeatedly called climate change fake, is now threatening Brazil with tariffs over the deforestation of the Amazon
Environment
Trump, who has repeatedly called climate change fake, is now threatening Brazil with tariffs over the deforestation of the Amazon
By Sasha RogelbergJune 8, 2026
2 days ago
Current price of silver as of Tuesday, June 9, 2026
Personal Finance
Current price of silver as of Tuesday, June 9, 2026
By Joseph HostetlerJune 9, 2026
22 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.