← All enforcement actions
GLBAFTC ActState AGFinancial Services

Equifax$700M+ GLBA fine (2017)

Largest consumer-data settlement in US history — Apache Struts patch ignored for 76 days

Penalty
$700M+
Regulator
FTC + CFPB + 50 State AGs
Jurisdiction
United States
Records affected
147M

What happened

Attackers exploited a known Apache Struts vulnerability (CVE-2017-5638) that Equifax had failed to patch for 76 days, exposing names, SSNs, DOBs, addresses, and driver's-license numbers of 147M Americans. The 2019 global settlement was at least $575M (potentially $700M+ including civil penalties and consumer fund top-ups).

Root cause

What every team should do

  1. Document a vulnerability-management SLA with named owner and enforced ticket queue
  2. Inventory + monitor all expirable assets (TLS certs, secrets, BAA dates)
  3. Segment the production network so a single web-app RCE cannot reach PII stores
  4. Pre-author breach-notification playbook with regulator + state-AG timelines
Source: FTC press release (Jul 2019), Equifax 8-K (Sep 2017).
Would your controls have stopped this?

ComplianceIQ audits your existing policies in 60 seconds and shows you exactly which GLBA controls you are missing — mapped to enforcement patterns like this one.

Run my GLBA audit Generate missing policies

Related enforcement actions

BetterHelp
$7.8M
Disclosed sensitive mental-health data to Meta / Snap ad pixels
Block / Cash App
$175M
Failed fraud investigations + inadequate Reg E dispute handling
Capital One
$80M + $190M class
Mis-configured AWS WAF → 106M records exfiltrated by a former AWS engineer
TJX Companies
~$256M
The breach that wrote PCI DSS — 94M cards stolen via insecure WEP wireless