People search Equifax data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 8 Equifax-linked incidents, with headline counts up to 163.1M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.
Why Equifax breach history matters
Equifax operates in Government (United States). Across indexed rows, recurring themes include cloud and database misconfiguration. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.
Full timeline through 2026
2017 — 13.8M records, 694K substantive
Cataloged incident. UK data on US servers. 13.8M UK records; 694K with substantive exposure. 14.5M names/DOB only. 15K had partial cards, passwords. FCA fined £11.16M in 2023. Exposed categories include Names, DOB, addresses, emails, driving licenses, partial cards. BreachHistory cites approximately 13.8M+ affected records in this row. See the equifax-uk2017 and canonical BreachHistory entry.
2017 — — Equifax: Equifax, which supplies credit information and…
Cataloged incident. Equifax, which supplies credit information and other information services, said Thursday that a data breach could have potentially affected 143 million consumers in the United States.Equifax said it discovered the breach on July 29. Criminals exploited a U.S. website application vulnerability to gain access to certain files, the company said.Equifax said exposed data includes names, birth dates, Social Security numbers, addresses and some driver's license numbers, all of which the company aims t Exposed categories include Personal information. BreachHistory cites approximately 145.5M+ affected records in this row. See the equifax2017 and canonical BreachHistory entry.
2017 — Apache Struts
Cataloged incident. Attackers exploited CVE-2017-5638 (Apache Struts 2 RCE) on an Equifax dispute portal. They gained a foothold, moved laterally, and exfiltrated PII including SSNs, names, birth dates, and addresses. The vulnerability had a patch available months before the breach; Equifax had not applied it to all systems. Exposed categories include Names, Addresses, Social Security numbers, Personal identifiable information. BreachHistory cites approximately 147.9M+ affected records in this row. See the fkzm and canonical BreachHistory entry.
2017 — — Equifax: Poor security / misconfiguration, 163,119,000 records
Cataloged incident. Data breach reported. financial organization. Method: poor security. Source: Wikipedia List of data breaches. Exposed categories include Personal and demographic data. BreachHistory cites approximately 163.1M+ affected records in this row. See the equifax2017-163119000-wiki2 and canonical BreachHistory entry.
2016 — — Equifax: Identity thieves stole tax and salary data from…
Cataloged incident. Identity thieves stole tax and salary data from big-three credit bureau Equifax Inc., according to a letter that grocery giant Kroger sent to all current and some former employees on Thursday. The nation’s largest grocery chain by revenue appears to be one of several Equifax customers that were similarly victimized this year. Atlanta-based Equifax’s W-2Express site makes electronic W-2 forms accessible for download for many companies, including Kroger — which employs more than 431,000 people Exposed categories include Personal information. BreachHistory cites approximately 431K+ affected records in this row. See the equifax2016 and canonical BreachHistory entry.
2012 — — Equifax: Equifax settled charges with the Federal Trade…
Cataloged incident. Equifax settled charges with the Federal Trade Commission after it was discovered that Equifax Information Services improperly sold lists of consumer data. People who were late on their mortgage payments had their information sold to firms that should not have received the information and subsequently resold it to other firms. Equifax agreed to pay nearly $1.6 million to resolve charges that it violated the FTC and Fair Credit Reporting Acts. The settlement prohibits Equifax from providing pre Exposed categories include Personal information. BreachHistory cites approximately 17K+ affected records in this row. See the equifax2012 and canonical BreachHistory entry.
2010 — — Equifax: An unknown number of current and former employees…
Cataloged incident. An unknown number of current and former employees of credit reporting firm Equifax received W-2 forms in the mail with their Social Security numbers visible through a window on the envelope. Some of the tax forms mailed by Equifax's payroll vendor through the U.S. Postal Service had the Social Security number in a Control Number field, which was partially or fully viewable through the return address window. Exposed categories include Personal information. BreachHistory cites approximately 35 affected records in this row. See the equifax2010 and canonical BreachHistory entry.
2006 — — Equifax: On May 29, a company laptop containing employee…
Cataloged incident. On May 29, a company laptop containing employee names and partial and full Social Security numbers was stolen from an employee. Exposed categories include Personal information. BreachHistory cites approximately 3K+ affected records in this row. See the equifax2006 and canonical BreachHistory entry.
Patterns and analysis
- Cloud and database misconfiguration — appears across multiple Equifax catalog entries; prioritize controls that address this class of failure.
- Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
- 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.
What to do if you may be affected
- Step 1: Enable phishing-resistant MFA on every account tied to this brand.
- Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
- Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
- Step 4: Bookmark the Equifax company page for new 2026+ disclosures.
Canonical BreachHistory hub
Explore every indexed row: breachhistory.com/equifax · Latest: equifax-uk2017.
Sources: BreachHistory catalog (8 rows for Equifax), company and regulator disclosures cited in individual breach records.