Three Equifax execs including CFO sold shares worth ~$1.8M days after breach found but before public disclosure; no filings list transactions as scheduled sales
Trio didn't know about the intrusion when selling, firm says — Shares tumbled in late trading after company disclosed breach
Context & Ripple Effects
Bloomberg's September 8 report landed between two disclosures: Equifax had revealed the breach affecting 143 million people days earlier, sending shares tumbling in late trading, and the trio's sales — about $1.8M by the CFO and two other executives days after the intrusion was found internally — were not listed as scheduled trades in any filing.
The story escalated quickly: sources told Bloomberg the DoJ opened a criminal investigation into the three executives' stock sales within two weeks, while reporting emerged that Equifax had discovered a separate major breach back in March that it said was unrelated to the hack. Months later, the company's special committee cleared the four senior executives who sold shares, finding they were unaware of the breach at the time.
First-order effects
- The three named executives, including the CFO, face immediate legal exposure — the absence of scheduled-sale filings removes the standard defense that the trades were pre-programmed, and shares fell sharply as soon as the breach became public.
Second-order effects
- Equifax is forced to respond with an internal mechanism rather than a routine statement — the special committee review exists precisely because the timing gap between internal discovery and public disclosure made the sales look actionable, and the finding that sellers were unaware becomes central to defusing both the criminal probe and shareholder litigation pressure.
Third-order effects
- If the pattern holds, breach-disclosure timelines become a de facto trading blackout window for insiders: companies will need auditable, pre-scheduled sale programs to survive the optics of any trade made between learning of a security incident and disclosing it, regardless of what the seller actually knew.
The trend: Cybersecurity incidents are collapsing the gap between a company's private knowledge and its market-facing obligations, turning every insider transaction in the disclosure window into potential evidence.