EQUIFAX INC.
ent_019de5f7748b763be41ccc9f62972c40
Disclosures
21
SEC 10-K Item 1C · State AG · 7 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
147,900,000
nationwide · State AG CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- EQUIFAX INC.
- Normalized
- equifax— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493004MCF8JDC86VS77
- SEC EDGAR CIK
- 0000033185
- Domain
- equifax.com
Disclosure history (21)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-02-19
Equifax disclosed a 2017 cybersecurity incident involving unauthorized access to its systems, resulting in the theft of personal information (PII, identity, IP) from consumers in the US, Canada, and UK. The attack exploited a public-facing application, leading to data exfiltration and encryption (ransomware). The incident was resolved, and the company implemented enhanced security controls, including MFA and employee training.
- New Hampshire State AGas victim2017-10-12
Equifax filed a supplemental notice with the New Hampshire Attorney General on October 12, 2017, updating the scope of the July 2017 breach. The incident, caused by exploitation of a web application vulnerability, impacted approximately 145.5 million U.S. consumers, including 634,614 New Hampshire residents. Data exposed included names, SSNs, DOBs, addresses, and driver's license numbers. Equifax engaged Mandiant for forensics and offered credit monitoring.
- South Carolina State AGas victim2017-09-12
Equifax filed a supplemental breach notice in South Carolina on October 13, 2017, covering 2.5 million additional U.S. consumers. The breach involved unauthorized access via exploitation of a web application vulnerability between mid-May and July 2017. Data exposed included names, SSNs, birth dates, addresses, and some credit card numbers. Equifax engaged forensic investigators and notified law enforcement.
- California State AGas victim2017-09-07
Equifax Inc. notified California residents of a supplemental determination regarding its 2017 data breach. Criminals exploited a website application vulnerability to gain unauthorized access to personal information from mid-May through July 2017. Equifax discovered the intrusion on July 29, 2017. This notice specifically addresses approximately 2.4 million additional U.S. consumers whose partial driver's license information was confirmed impacted, bringing the total nationwide affected count to approximately 147.9 million. The data involved names, driver's license numbers, dates of birth, and in some cases addresses. Equifax offered 12 months of identity theft protection and credit monitoring.
- Washington State AGas victim2017-09-07
Equifax, Inc. filed a supplemental notice with the Washington Attorney General regarding a cybersecurity incident. The breach, caused by the exploitation of a web application vulnerability, occurred from May 16 to July 31, 2017, and was discovered on July 29, 2017. The incident impacted approximately 145.5 million U.S. consumers, including 3,243,664 Washington residents. Data exposed included names, SSNs, birth dates, addresses, driver's license numbers, and credit card numbers. Equifax engaged Mandiant for forensic investigation and offered free credit monitoring.
- New Hampshire State AGas victim2017-09-07
Equifax Inc. notified New Hampshire AG of a cybersecurity incident discovered July 29, 2017, where criminals exploited a web application vulnerability to access files. Approximately 143 million U.S. consumers affected, including 622,558 NH residents. Data included names, SSNs, DOBs, addresses, driver's licenses, and some credit card numbers. Equifax engaged forensic investigators, notified law enforcement, and offered one year of free credit monitoring.
- Oregon State AGas victim2017-09-07
Equifax Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2017-09-07. The breach occurred during 5/13/2017 - 7/30/2017. The breach was discovered on 7/29/2017. 143,000,000 individuals were affected. Notice was sent on 9/7/2017.
- Massachusetts State AGas victim2017-09-07
Equifax, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-09-07. 2,982,421 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2017-02-09
Equifax reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-02-09. 3 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2017-02-08
Equifax Consumer Services LLC notified the NH Attorney General of a data security incident affecting 1 NH resident. On Jan 6, 2017, LifeLock reported a member could view another's credit report. Equifax determined credit info for 158 LifeLock members was inadvertently sent to another member's portal due to a technical issue, not malicious activity. Notifications were mailed on Feb 8, 2017, and LifeLock subscriptions were extended for 12 months.
- New Hampshire State AGas victim2015-06-05
Equifax, a third-party vendor for Rite Aid, experienced an insider threat incident where a former employee misused access privileges to reset accounts and access PII (SSN, payroll info) of Rite Aid employees. The incident occurred Jan-Feb 2015. Rite Aid notified NH AG on June 5, 2015. Affected individuals received notification and credit monitoring services.
- Massachusetts State AGas victim2015-04-08
Equifax Information Services reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2015-04-08. 19 Massachusetts residents were affected. The report records the breach type as both.
- New Hampshire State AGas victim2015-04-02
Equifax notified the New Hampshire Attorney General on April 2, 2015, of a data incident affecting one NH resident. On March 15, 2015, Equifax discovered a technical error during a software change that resulted in the inadvertent mailing of one resident's PII (including SSN and account numbers) to incorrect individuals. Equifax addressed the error, attempted to retrieve the data, and offered one year of ID Patrol protection.
- Massachusetts State AGas victim2014-03-11
Equifax, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2014-03-11. 34 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2012-12-21
Equifax reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2012-12-21. 16 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2010-08-02
Equifax, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2010-08-02. 20 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2010-07-01
Equifax, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2010-07-01. 3 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2010-04-05
Equifax Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2010-04-05. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2010-03-22
Equifax Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2010-03-22. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2010-02-18
Equifax Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2010-02-18. 79 Massachusetts residents were affected. The report records the breach type as paper.
- New Hampshire State AGas victim2010-02-10
Equifax notified the NH Attorney General of a security incident involving 14 NH residents. On Jan 19, 2010, Equifax discovered that W-2 forms mailed to employees via a payroll vendor had SSNs visible through the envelope window. Equifax notified affected employees and offered one year of free credit monitoring.
Subsidiary disclosures (9)filed by group companies
◈ These filings were made by or about subsidiaries of EQUIFAX INC. — not by EQUIFAX INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Oregon State AGvia Equifax Consumer Services LLC2018-02-08
Equifax Consumer Services LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2018-02-08. The breach occurred during 8/1/2017 - 9/2/2017. 36 individuals were affected. Notice was sent on 1/29/2018.
- Massachusetts State AGvia TALX2017-08-28
TALX Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-08-28. 30 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGvia TALX2017-07-21
TALX Corporation, a payroll services provider, notified the NH Attorney General of a data security incident affecting 12 NH residents (employees/family of Whole Foods Market). Unauthorized third parties accessed online portal accounts between April 2016 and April 2017 by answering personal security questions to reset PINs. Exposed data included W-2s, 1095-Cs, SSNs, names, addresses, and health insurance info. TALX notified law enforcement/IRS, enhanced security, disabled personal questions, and offered 2 years of identity protection.
- Massachusetts State AGvia TALX2017-07-17
TALX Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-07-17. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGvia TALX2017-07-03
TALX Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-07-03. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGvia TALX2017-06-02
TALX Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-06-02. 5 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGvia TALX2017-05-23
TALX Corporation, a payroll services provider for Allegis Group, reported unauthorized access to employee online portal accounts between January 4, 2016, and March 29, 2017. Attackers reset PINs by answering personal security questions, accessing W-2 and 1095-C tax forms containing SSNs, names, addresses, and earnings/health insurance data. TALX notified law enforcement and implemented enhanced fraud monitoring and PIN resets.
- Washington State AGvia TALX2017-05-15
TALX Corporation, a subsidiary of Equifax, disclosed a cyberattack affecting payroll data for Allegis Group employees. Unauthorized parties accessed accounts between Jan 2016 and Mar 2017 by answering personal security questions to reset PINs. Data exposed included names, SSNs, DOBs, and financial info. 1,467 Washington residents were notified in May 2017. TALX engaged forensic investigators, enhanced security controls, and offered 2 years of identity protection.
- Montana State AGvia TALX2017-05-11
TALX Corporation, a subsidiary of Equifax, notified individuals of unauthorized access to payroll portal accounts between Jan 2016 and Mar 2017. Attackers used personal info to reset PINs. Data exposed included W-2/1095-C forms, SSNs, names, addresses, and financial info. TALX notified law enforcement and IRS, reset credentials, and provided 24 months of identity protection.