Equifax was allegedly hacked months before the massive breach — by the same criminals

And at least one person says the same crew was responsible.
 By 
Jack Morse
 on 
Equifax was allegedly hacked months before the massive breach — by the same criminals
Jeez. Credit: RHONA WISE/EPA-EFE/REX/SHUTTERSTOCK

Equifax was hacked this past summer. You already know this. However, according to a new report, the company's computer systems were also allegedly broken into in March. And here's the kicker: The same crew might be responsible for both incidents.

That's right, the same culprits behind the theft of personal information on potentially 143 million Americans might have been poking around in Equifax's databases months earlier.

The news comes to us via Bloomberg, which notes that "three people familiar with the situation" told the publication about the alleged March intrusion. One of those three people claim "the breaches involve the same intruders."

And it's not like Equifax didn't know about it at the time. As Bloomberg reports, the company hired a cybersecurity firm to investigate the March breach. But wait, it gets worse.

That potentially the same hackers may have been able to return to Equifax's systems to pilfer massive amounts of information is especially baffling considering the vulnerability the hackers reportedly used in the more recent breach was known in March, according to Bloomberg.

However, the problem wasn't fixed until the second hack was detected in July, the publication reports. That massive hack took place between May and July.

"We know that criminals exploited a US website application vulnerability," a company spokesperson wrote on September 15. "The vulnerability was Apache Struts CVE-2017-5638."

Again, that Apache Struts vulnerability was reportedly known in March — meaning the company could very likely have prevented the incident later announced on September 7. The company was aware it had been breached and had the tools to fix a major problem with its site. And yet.

In a statement to Bloomberg, however, Equifax claimed that the two hacks were unrelated. Meanwhile, The Wall Street Journal cites an unnamed source "familiar with the investigation" as saying that it looks like the hack was probably state-sponsored. No information was provided to back up that claim.

This revelation will surely complicate matters for the Equifax executives who sold close to $2 million in stock before the public was alerted to the breach. The Senate Finance Committee is looking into the matter.

Topics Cybersecurity

Mashable Image
Jack Morse

Professionally paranoid. Covering privacy, security, and all things cryptocurrency and blockchain from San Francisco.

Mashable Potato

Recommended For You

Panera Bread breach: ShinyHunters claims hack of 14 million customers' data
Panera Bread logo on storefront

Instagram denies data breach: So what's up with those sketchy change password emails?
instagram logo against a black background

The European Commission got hacked for the second time this year
Europe flag

Get 2 free months of unlimited listening when you sign up for Amazon Music Unlimited
Amazon Music Unlimited logo with teal and orange background

Trending on Mashable
NYT Connections hints today: Clues, answers for April 4, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 4, 2026
Wordle game on a smartphone


NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!