Equifax discovered major breach in March but says it's unrelated to recently disclosed hack affecting 143M people; source says both involve the same intruders
New timeline could have implications for executive stock sales — The company is the subject of multiple investigations
Context & Ripple Effects
Equifax's disclosure timeline was already under strain before this report: the breach affecting up to 143M consumers was found on July 29 and disclosed in September, and in between three executives including the CFO sold roughly $1.8M in shares with no filings marking them as scheduled sales — transactions now under a DoJ criminal investigation.
The new wrinkle is a second, earlier breach discovered in March that Equifax insists is unrelated to the big one, while a source says both involve the same intruders. That collides directly with the former CEO's admission that patching took months after a March DHS alert, and with findings that the hack may be state-sponsored with 30+ entry points created in Equifax systems.
First-order effects
- Equifax's 'unrelated' framing is contradicted by its own sourcing, handing the DoJ and other investigators a plausible March knowledge date that predates the July 29 discovery and stretches the window around the executives' stock sales.
- The three investigated executives face an expanded theory of exposure: if the same intruders were inside since March, their trades look less like routine sales timed near a known incident and more like trades during a months-long compromise.
Second-order effects
- With 30+ entry points and possible state sponsorship, a March start extends suspected attacker dwell time from weeks to months, widening the population of potentially exposed records beyond the 143M–145.5M already acknowledged and scaling Equifax's remediation and consumer-protection obligations accordingly.
- The multiple open investigations pivot from disclosure mechanics to core security posture: whether Equifax knew of an intrusion in March, failed to patch promptly after the DHS alert, and still permitted insider selling becomes the through-line regulators and prosecutors pursue.
Third-order effects
- If a March discovery followed by slow patching and pre-disclosure trading hardens into the accepted record, breach-response timelines become securities-liability evidence, pressuring companies to disclose faster and restrict insider trading once an intrusion is detected.
- The episode sharpens structural scrutiny on centralized custodians of SSN-level data: one compromise at a single credit bureau exposes the household identity layer for millions, feeding arguments for decentralizing or re-regulating who holds that data.
The trend: Breaches at identity-data custodians are shifting from IT incidents into securities and governance crises, where disclosure speed, patching delays, and insider trades determine the legal fallout.