Equifax
One of three major US credit bureaus that lost 147 million records and nearly destroyed itself - not because of the breach, but because every alarm system failed.
One of three major US credit bureaus that lost 147 million records and nearly destroyed itself - not because of the breach, but because every alarm system failed.
In 2017, Equifax didn't just suffer a data breach. It demonstrated what organizational death looks like in slow motion. The attack exploited a known Apache Struts vulnerability that had a patch available for months. Equifax didn't apply it. This is genomic instability: accumulated technical debt (DNA damage) that wasn't repaired because the company skipped maintenance - the corporate equivalent of sirtuins, the cellular repair systems that prevent cancer.
But the breach itself wasn't fatal. The alarm system failures were. Ten weeks to detect the breach (alarms failed or ignored). Six weeks between detection and disclosure (delayed response). When finally disclosed, chaos: website crashed, phone lines jammed, defensive messaging, and CEO statements contradicting previous security claims. The credibility collapse was total.
The biological lesson: organisms don't die from single mutations - they die when repair systems fail and damage cascades. Equifax's result: CEO resignation, $700 million in fines, permanent reputational damage, and a textbook case of how organizations crumble when prevention, detection, and response all fail simultaneously.
Cautionary Notes on Equifax
- 10-week detection delay - intrusion detection failed or alerts ignored
- 6-week disclosure delay after detection (potential insider trading)
- Website crashed immediately when breach disclosed
- Attempted to force breach victims to waive legal rights
- Previous 'we take security seriously' claims created credibility collapse
- 147M customer records lost from unpatched vulnerability
- Example of skipped maintenance leading to catastrophic failure
Equifax Appears in 2 Chapters
The 2017 data breach exposed 147 million records and demonstrated catastrophic alarm system failures: 10-week detection delay, 6-week disclosure delay, and total credibility collapse.
Read about alarm systems →Equifax's failure to patch a known vulnerability for months represents organizational genomic instability - technical debt that accumulated until catastrophic failure.
Read about maintenance and longevity →