Skip to Content

Equifax: 147 Million Records, 76 Days Undetected

What the largest credit data breach in history teaches about the window of time when nobody notices anything
September 9, 2026 by
Equifax: 147 Million Records, 76 Days Undetected

147 million records and 76 days without detection: the Equifax case

In September 2017, Equifax, one of the world's largest credit information companies, publicly disclosed that attackers had gained access to the personal data of roughly 147 million consumers. The announcement placed an organization entirely dedicated to assessing other people's risk at the center of one of the decade's biggest cyber risk discussions.

Later official reports detailed the public dimension of the episode. According to report GAO-18-559, from the United States Government Accountability Office, the improper access involved an internet-facing web application and went undetected for approximately 76 days. The exposed data included names, Social Security numbers, dates of birth, addresses and, in some cases, document and card numbers.

The financial outcome came in 2019, when the company reached a global settlement with the FTC, the CFPB and state attorneys general, with a fund of up to US$ 700 million earmarked for affected consumers, according to the Federal Trade Commission. Added to that amount were the company's own billion-dollar figures for remediation and security restructuring, something close to the US$ 1.4 billion the company declared in filings to investors.

Nothing that has been published entitles any outsider to state what exactly failed inside that organization, which controls existed or how internal decisions were made. The case's value to you, as a decision-maker, lies elsewhere: it exposes, with figures audited by public agencies, the real cost of a window of time in which someone moves around inside an environment without anyone noticing. That window exists in practically every company that still treats security as a one-off project.

Vectors that incidents of this type usually exploit

Although the internal details of the incident are not public, attacks against environments that hold sensitive data tend to exploit a small, repetitive set of entry points. Knowing these vectors allows you to assess your own structure with concrete questions, instead of relying on impressions.

Known and unpatched vulnerabilities. There is a dangerous distance between the day a vendor releases the fix for a flaw and the day that fix actually reaches every server, application and workstation in your company. In that interval, the flaw is already public, exploit code is already circulating and automated bots are already scanning for it en masse. Verizon's Data Breach Investigations Report 2024 found that the exploitation of vulnerabilities as an initial access vector grew 180% in one year and accounted for 14.3% of the breaches analyzed. A system published on the internet with a patch delayed by a few weeks works as a silent invitation, especially when no one maintains a complete inventory of what is exposed.

Lack of continuous proactive monitoring. Attackers rarely cause damage in the first minute, because they need to survey the environment, escalate privileges and locate where the data worth money is. This dwell period is precisely the defense opportunity, and it is usually wasted. IBM's Cost of a Data Breach 2024 report calculated a global average of 194 days to identify a breach and 292 days to fully contain it, with an average cost of US$ 4.88 million per incident. Without someone watching for anomalous account behavior, atypical query volumes against the databases and unusual outbound connections, the alert ends up arriving from the customer, the regulator or the press.

Compromised credentials and an unsegmented network. A reused password, a third-party access that remained active after the contract ended or a service account with broad privileges open the door without a sound, since the attacker walks in dressed as a legitimate user. The problem multiplies when the network is flat, that is, when whoever reaches a secondary server can move laterally all the way to critical databases without encountering any division along the way. An honest thought experiment is worth it: if an administrative credential from your company leaked tomorrow, how many systems would it open before running into a second authentication factor?

Layered protection: what you can do in your own structure

No single technology prevents a well-built attack, and effective defense works as layers that buy time and reduce reach. The first layer is continuous patch and vulnerability management, supported by a live asset inventory, with absolute priority for everything published on the internet and remediation cycles measured in days. A mature approach to managed cybersecurity treats this routine as a permanent process, with documented evidence of application on each asset.

The second layer combines endpoint protection with EDR (Endpoint Detection and Response), which records behavior on each machine and makes it possible to isolate a compromised device before lateral movement advances, together with multi-factor authentication (MFA) on all administrative, remote and external partner access. Add to that network segmentation, separating sensitive data environments from general-purpose workstations, so that a single compromise does not hand over the entire business.

The third layer is continuous proactive monitoring, with intelligent alerts that correlate events from multiple sources and turn noise into actionable priority. The practical goal of this layer is to reduce the interval between the first anomalous signal and the first human containment action, because every hour saved at this stage converts directly into less exposed data and lower remediation cost.

The fourth layer supports recovery: backup isolated from the production domain, encrypted and tested with real restores on a defined schedule, accompanied by a business continuity and disaster recovery plan documented, with defined roles, deadlines, and communication plans. Complete the set with ongoing user training, since the Verizon DBIR 2024 recorded human factor involvement in 68% of the breaches analyzed.

Questions every decision-maker should be asking right now

  1. Would my backups actually work in a disaster like this one? How long until my operation is back up and running?
  2. Does my team have the right tools to identify and block an attack like this immediately, before it causes a full-blown disaster? How am I investing in preparing my technical team?
  3. How long would my company survive without access to its systems and files?

Would my backups actually work in a disaster like this one?

A backup only truly exists once it has actually been restored, with the clock running and witnesses in the room. Define the RTO (Recovery Time Objective, the maximum acceptable time until operations resume) and the RPO (Recovery Point Objective, the maximum volume of data you are willing to lose) for each critical system, and then verify whether your current infrastructure delivers those numbers. Copies isolated from the production domain, immutable and encrypted, prevent the same access capable of compromising the environment from also reaching your last line of recovery.

Does my team have the right tools to block an attack immediately?

A tool without a process produces alerts that nobody reads, and a process without a tool produces effort that does not scale. Evaluate three elements together: endpoint detection and response with real isolation capability, continuous proactive monitoring that separates noise from incident, and a documented response plan with named roles and periodic simulations. Preparing the technical team belongs in the same budget as the technology, because the people operating it need time, training, and specialized backup support to act safely under pressure.

How long would my company survive without access to its systems and files?

Turn the question into a number before an incident does it for you: multiply the cost of one hour of downtime, adding up idle payroll, suspended revenue, contractual penalties, and reputational damage, by the realistic recovery time your structure delivers. When the result of two or three days of downtime far exceeds the annual investment in layered protection, the discussion moves out of the technical arena and into the financial one, with a calculation any board understands.

If your company does not yet have an integrated layered protection strategy, consider requesting a Strategic IT Assessment, with no obligation, to identify vulnerabilities before they become headlines.


Frequently asked questions

What does it mean to say an attack went 76 days without detection?

It means the unauthorized access remained active for that period before being identified by the organization. This interval is called dwell time and represents the window in which the attacker surveys the environment, escalates privileges, and collects data. Reducing that time depends on continuous proactive monitoring and on endpoint detection and response.

Is cloud backup enough to protect a company from a data breach?

Backup addresses the availability of information and the resumption of operations after downtime or data destruction. Confidentiality depends on other controls, such as access management, encryption, network segmentation, multifactor authentication, and continuous monitoring. The two fronts are complementary and need to coexist within the same strategy.

How often should I test the restoration of my backups?

A consistent practice is to run full restoration tests at least quarterly on critical systems, recording the actual time until operations resume. Monthly partial tests on smaller databases help detect silent copy failures before they accumulate. The test gains value when it measures the time to resume operations, in addition to file integrity.

Equifax: 147 Million Records, 76 Days Undetected
September 9, 2026
Share this post
Tags
Archive