Every day brings new details—and questions—about the Equifax breach that exposed the personal information of millions of customers to hackers. It can be hard to keep up with the firehose of information; that’s where we come in.


Every day brings new details—and questions—about the Equifax breach that exposed the personal information of millions of customers to hackers. It can be hard to keep up with the firehose of information; that’s where we come in.
Here’s everything you need to know about what’s going on, and what exactly you should be doing to deal with it.
Join 500,000+ readers who start their day with Quartz.
By subscribing, you agree to our Terms of Service and Privacy Policy.
Equifax is one of three major credit reporting agencies (CRAs) in the US. The other two are TransUnion and Experian. These agencies maintain records on all Americans’ credit history by gathering data from firms that issue credit, such as credit card companies, banks, and credit unions.
On Sept. 7, Equifax reported that hackers had exploited a vulnerability in its US website application to gain access to certain files from mid-May through July 2017.
The hackers accessed personal data, including Social Security numbers, birth dates, addresses, and, in some cases, driver’s license numbers. They also stole credit card numbers (at least) for approximately 209,000 US consumers, as well as dispute documents—used to dispute errors on credit reports—with personal identifying information for approximately 182,000 US consumers. Some UK and Canadian residents may have also had personal data compromised.
If you are an American citizen or US resident and you have ever applied for credit, you could have been affected by the breach, according to the Identity Theft Resource Center. (After all, 143 million people represents 44% of the US population.) Says ITRC: “The breach may also impact minor children whose parents have submitted documentation to the CRAs for the purposes of checking on or protecting their credit information, even if a credit report or score was never established.”
You read that right. The company discovered the breach on July 29 and chose not to publicly disclose it until last week. Adding insult to injury, three Equifax executives sold nearly $2 million in company stock before the announcement. The company maintains that its executives “had no knowledge that an intrusion had occurred at the time they sold their shares.”
Perhaps unsurprisingly, Equifax is now under federal investigation. On Friday, Dow Jones reported that two of its security and information executives are retiring, effective immediately.
The company established a website to help consumers find out whether their data had been compromised; it also offered them the opportunity to sign up for credit-file monitoring and identity-theft protection.
When the Equifax recovery site first launch, it included a clause stating that anyone signing up for protective services waived their rights to participate in any class-action lawsuits against the company. After intense public and media outcry, the company eventually removed the clause.
Again, if you are an American citizen or US resident who has applied for credit, this applies to you! Here is a quickie version of Quartz’s guide to navigating the fallout.
ITRC CEO Eva Casey Velasquez says that taking a wait-and-see approach could be hugely detrimental. Credit fraud can take weeks to resolve, at best; at worst, it can take years. That hassle far outweighs the inconvenience of having a temporary (or even permanent) credit freeze.
Having your SSN stolen also puts you at risk for criminal, medical, and even government benefits and documents fraud, Velasquez says. To avoid tax fraud, file early.
(You can read more of Velasquez’s advice here.)
By Wired’s count, there have been 23 cyberattacks in 2017, ranging from a Verizon $VZ server vulnerability that left the phone numbers, names, and pin codes of 6 million customers exposed to a malware attack on Chipotle $CMG’s payment systems that accessed US customers’ payment card data.
“Your Social Security number is supposed to be kept secret, which is an increasing challenge in the digital era,” Wired noted in a story this week. “And unlike other, similar secrets (like credit card numbers and passwords), SSNs are extremely difficult to change.”
Many experts are now calling for a complete revamp of the SSN system, or even eliminating it entirely.
Updated (Oct. 4, 2017): Equifax announced on Oct. 2 that the total number of consumers affected has risen to 145.5 million. We have updated the story.