The object is not "Equifax is sloppy" or "patch faster." It is a consumer reporting agency whose online dispute portal still ran Apache Struts CVE-2017-5638 after US-CERT told everyone to patch, after Equifax emailed more than 400 people with a 48-hour order, after a scan that found nothing. Attackers then sat on that portal for 76 days, ran about 9,000 queries, used plaintext administrative credentials, and took Social Security numbers of about 145.5 million people who never chose Equifax as a vendor. The inspection device in front of the portal had an expired certificate, so the exfiltration looked like ordinary encrypted traffic. The portal was not kept apart from 48 other databases.
Domain: a credit bureau that compiles files on people who cannot opt out, with a public web application that talks to those files. The comparison class is any firm whose "we forwarded the CERT alert" step is treated as a security action, especially when the people in the files never contracted with the firm.
If that reading is right, a US-CERT notice and a mass email would not count as patched. A 48-hour policy would not count unless the scan actually finds the instance. A dispute portal would not sit on the same network as 145 million Social Security numbers. Credit monitoring after the fact would not count as the repair. Two other bureaus receiving the same alert and applying the same patch would be the discriminator, not a press release.
Ostensive specimen: U.S. Government Accountability Office, GAO-18-559, "Data Protection: Actions Taken by Equifax and Federal Agencies in Response to the 2017 Breach," August 2018, publicly released 7 September 2018. Attackers used a known Apache Struts vulnerability on the online dispute portal. From 13 May 2017 they extracted personal information; Equifax discovered the intrusion on 29 July, about 76 days later. About 9,000 database queries; access expanded from three portal databases to 48 unrelated ones using unencrypted usernames and passwords. Four factors Equifax named: identification (the March CERT notice went to an out-of-date list; a later scan did not find Struts on the portal), detection (an expired digital certificate, about ten months, so encrypted traffic was not inspected), segmentation, and data governance. At least 145.5 million U.S. consumers, and nearly one million outside the U.S. https://www.gao.gov/products/gao-18-559 PDF: https://www.gao.gov/assets/gao-18-559.pdf
What the civil complaint already names, not recap. Federal Trade Commission v. Equifax Inc., N.D. Ga., complaint filed 22 July 2019. Equifax stores personal information about more than 200 million U.S. consumers. The Automated Consumer Interview System (ACIS) handles disputes, freezes, fraud alerts, and AnnualCreditReport.com requests. Equifax's own documents called it "archaic." On or about 8 March 2017, US-CERT alerted Equifax to CVE-2017-5638. The next day Equifax emailed more than 400 employees to patch within 48 hours. The email did not reach the employee responsible for the ACIS dispute portal. A 15 March scan was not configured to search all public-facing assets and found nothing. Between 13 May and 30 July, multiple attackers exploited the portal, crawled unrelated databases, and used plaintext administrative credentials on an unsecured file share. Nearly ten thousand queries. About 147 million names and dates of birth, 145.5 million Social Security numbers, 99 million addresses, 209,000 payment card numbers. Social Security numbers stored in plain text, contrary to Equifax's own encryption policy. https://www.ftc.gov/system/files/documents/cases/172_3203_equifax_complaint_7-22-19.pdf Settlement press, 22 July 2019: at least $575 million, potentially up to $700 million, with the CFPB and 50 U.S. states and territories. "Equifax failed to take basic steps that may have prevented the breach that affected approximately 147 million consumers." https://www.ftc.gov/news-events/news/press-releases/2019/07/equifax-pay-575-million-part-settlement-ftc-cfpb-states-related-2017-data-breach
The House record of the same split. Committee on Oversight and Government Reform, majority staff report, "The Equifax Data Breach," December 2018. "Consumers do not voluntarily provide information to CRAs, nor do they have the ability to opt out of this information collection process." ACIS, a custom-built internet-facing dispute portal, was running the vulnerable Struts version and was not patched. Attackers ran 9,000 queries on 48 databases and found unencrypted personal information 265 times. The device used to monitor ACIS traffic had been inactive for 19 months because of an expired certificate. Victim count grew to 148 million. Equifax allowed over 300 security certificates to expire, including 79 for monitoring business-critical domains. The report calls the breach "entirely preventable." https://oversight.house.gov/wp-content/uploads/2018/12/Equifax-Report.pdf Committee page: https://oversight.house.gov/report/committee-releases-report-revealing-new-information-on-equifax-data-breach/
What the former CEO put in the hearing record, not an employee's story. Prepared testimony of Richard F. Smith before the House Energy and Commerce Subcommittee on Digital Commerce and Consumer Protection, 3 October 2017. US-CERT notice 8 March 2017. Internal email 9 March, 48-hour patch policy. "We now know that the vulnerable version of Apache Struts within Equifax was not identified or patched." Scans on 15 March "did not identify the Apache Struts vulnerability." First access of sensitive information on or about 13 May; portal taken offline 30 July. Hearing: https://www.congress.gov/event/115th-congress/house-event/106455 Testimony: https://docs.house.gov/meetings/IF/IF17/20171003/106455/HHRG-115-IF17-Wstate-SmithR-20171003.pdf
The patch that was already public. Apache Struts S2-045: possible remote code execution on file upload via the Jakarta Multipart parser; a bad Content-Type throws an exception that is then used as an error message. Upgrade to 2.3.32 or 2.5.10.1. CVE-2017-5638. https://cwiki.apache.org/confluence/display/WW/S2-045 CISA, still live, 8 March 2017: a remote attacker could take control of an affected system; review S2-045 and upgrade. https://www.cisa.gov/news-events/alerts/2017/03/08/apache-software-foundation-releases-security-updates Equifax, 15 September 2017, named the vector as CVE-2017-5638 on the U.S. online dispute portal, access from 13 May through 30 July. https://investor.equifax.com/news-events/press-releases/detail/237/equifax-releases-details-on-cybersecurity-incident Apache Software Foundation, 14 September 2017: the compromise "was due to their failure to install the security updates provided in a timely manner." https://news.apache.org/foundation/entry/media-alert-the-apache-software
The control group in the same industry, not a hypothetical. Senate Permanent Subcommittee on Investigations, "How Equifax Neglected Cybersecurity and Suffered a Devastating Data Breach," 6 March 2019. A 2015 patch-management audit found a backlog of over 8,500 known vulnerabilities and what the auditors called an "honor system" for patching. Equifax never ran another such audit before 2017. TransUnion began patching vulnerable Struts versions within days of the same public alert. Experian retained a firm to scan for Struts, found a vulnerable server, took it offline, and began patching. https://www.hsgac.senate.gov/wp-content/uploads/imo/media/doc/FINAL%20Equifax%20Report.pdf
This post is the public case, not a recap of an essay.