FEDERALHackingVulnerability ExploitStolen CredentialsData ExfiltratedData EncryptedCustomer Data InvolvedDelayed DiscoveryMulti-Stage ChainRansom DemandedPIIIDENTITY_BASICIDENTITY_GOVERNMENTIPMediumResolved
EQUIFAX INC.
bd_e4ad2c4cce455cfc · schema v1 · pii pii-v1
Full breach record for EQUIFAX INC. →Equifax disclosed a 2017 cybersecurity incident involving unauthorized access to its systems, resulting in the theft of personal information (PII, identity, IP) from consumers in the US, Canada, and UK. The attack exploited a public-facing application, leading to data exfiltration and encryption (ransomware). The incident was resolved, and the company implemented enhanced security controls, including MFA and employee training.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/33185/000003318526000010/efx-20251231.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 19, 2026
- Raw hash
- 7279768c75f5a62508da261db27a6cd441fc81d04bacb42a0a0fa55144bc255c
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- EQUIFAX INC.norm: equifax
- SEC CIK
- 0000832463
- Domain
- equifax.com
Victim entity
- Name
- EQUIFAX INC.norm: equifax
- SEC CIK
- 0000832463
- Domain
- equifax.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICIDENTITY_GOVERNMENTIP
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified HHSState AG investigation opened
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.