Skip to Content

Nope, We Can’t Trust Data Firms to Update Against Known Security Flaws

September 14, 2017

It seems Equifax was hacked using a two-month-old vulnerability that it could have protected itself against.

"We know that criminals exploited a U.S. website application vulnerability,” the company wrote in a statement. “The vulnerability was Apache Struts CVE-2017-5638.” But as Ars Technica points out, that flaw was identified and fixed on March 6, with a patch (albeit a complex and finicky one to implement) offered to users of the Web app software so that they didn’t get hacked. Equifax was hacked in mid-May, a full two months after the vulnerability was announced. In other words, it looks like Equifax fell foul of a known exploit that it hadn't yet updated its systems against.

That would be careless if it was a security flaw on, say, your own home computer. But when failure to update software with a vulnerability like that—which, as Ars Technica has also reported, was used heavily by hackers in March—can result in the loss of personal data from as many as 143 million Americans, it’s negligent. And when a company claims, like Equifax, to be in the business of fraud prevention, identity management, and selling advice on how to manage data breaches? Well, I guess then we just find ourselves in the modern-day couldn’t-care-less corporate approach to cybersecurity.

Equifax’s CEO, Richard Smith, is due to testify before the House of Representatives on October 3. Let’s hope he's given a real hard time.

Deep Dive


Our best illustrations of 2022

Our artists’ thought-provoking, playful creations bring our stories to life, often saying more with an image than words ever could.

How CRISPR is making farmed animals bigger, stronger, and healthier

These gene-edited fish, pigs, and other animals could soon be on the menu.

The Download: the Saudi sci-fi megacity, and sleeping babies’ brains

This is today’s edition of The Download, our weekday newsletter that provides a daily dose of what’s going on in the world of technology. These exclusive satellite images show Saudi Arabia’s sci-fi megacity is well underway In early 2021, Crown Prince Mohammed bin Salman of Saudi Arabia announced The Line: a “civilizational revolution” that would house up…

10 Breakthrough Technologies 2023

Every year, we pick the 10 technologies that matter the most right now. We look for advances that will have a big impact on our lives and break down why they matter.

Stay connected

Illustration by Rose Wong

Get the latest updates from
MIT Technology Review

Discover special offers, top stories, upcoming events, and more.

Thank you for submitting your email!

Explore more newsletters

It looks like something went wrong.

We’re having trouble saving your preferences. Try refreshing this page and updating them one more time. If you continue to get this message, reach out to us at with a list of newsletters you’d like to receive.