EQUIFAX INC.
ent_019de5f7748b763be41ccc9f62972c40
Disclosures
5
SEC 10-K Item 1C · State AG · 5 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
145,700,000
nationwide · State AG CA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- EQUIFAX INC.
- Normalized
- equifax— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493004MCF8JDC86VS77
- SEC EDGAR CIK
- 0000033185
- Domain
- equifax.com
Disclosure history (5)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-02-19
Equifax disclosed a 2017 cybersecurity incident involving unauthorized access to its systems, resulting in the theft of personal information (PII, identity, IP) from consumers in the US, Canada, and UK. The attack exploited a public-facing application, leading to data exfiltration and encryption (ransomware). The incident was resolved, and the company implemented enhanced security controls, including MFA and employee training.
- 🦬Montana State AGas victim2018-03-01
Equifax reported a data breach to the Montana Attorney General. The breach was reported on 2018-03-01. The breach occurred from 7/29/2017 to 9/7/2017. 377,052 Montana residents were affected.
- 🐻California State AGas victim2017-09-07
Equifax Inc. filed a supplemental California SB-24 breach notification regarding a 2017 cybersecurity incident. Criminals exploited a website application vulnerability to access data from mid-May to July 2017. The breach impacted approximately 143 million U.S. consumers initially, with an additional 2.5 million consumers identified later, and a further 2.4 million consumers identified in March 2018 whose partial driver's license information was stolen. Data types included names, driver's license numbers, dates of birth, and Social Security numbers. Equifax engaged forensic investigators, notified law enforcement, and offered credit monitoring services.
- 🌲Washington State AGas victim2017-09-07
Equifax, Inc., a finance sector entity reported a other incident to the Washington Attorney General. The organization became aware of the incident on 2017-07-29 and filed notice on 2017-09-07. 3,243,664 Washington residents were affected. 40 days elapsed between awareness and notification. 74 days to identify the breach. 2 days to contain the breach.
- 🦫Oregon State AGas victim2017-09-07
Equifax Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2017-09-07. The breach occurred during 5/13/2017 - 7/30/2017. The breach was discovered on 7/29/2017. 143,000,000 individuals were affected. Notice was sent on 9/7/2017.
Subsidiary disclosures (1)filed by group companies
◈ These filings were made by or about subsidiaries of EQUIFAX INC. — not by EQUIFAX INC. itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.