2017 major breach — Apache Struts
Data compromised
Names, Addresses, Social Security numbers, Personal identifiable information
Technical writeup
Attackers exploited CVE-2017-5638 (Apache Struts 2 RCE) on an Equifax dispute portal. They gained a foothold, moved laterally, and exfiltrated PII including SSNs, names, birth dates, and addresses. The vulnerability had a patch available months before the breach; Equifax had not applied it to all systems.
Root cause
Unpatched Apache Struts 2 (CVE-2017-5638) on internet-facing application; insufficient patch management and network segmentation.