Researcher says they warned Equifax about vulnerability on public-facing site that exposed user data months before breach, but it took six months to patch it
Lorenzo Franceschi-Bicchierai / Motherboard : Tweets: @lorenzofb , @selenalarson , @derektmead , and @jason_koebler Tweets: Lorenzo Franceschi-B / @lorenzofb : In 2016 a researcher warned Equifax of a site where anyone could access SSNs, names & birthdates. EFX did nothing. https://motherboard.vice.com/ ... Selena Larson / @selenalarson : Security at Equifax sounds like a nightmare https://motherboard.vice.com/ ... @derektmead : Equifax was told of its huge security flaws, did nothing. What does this mean for liability? https://motherboard.vice.com/ ... Jason Koebler / @jason_koebler : All of Equifax's data was available on the internet, to anyone. Unencrypted and in cleartext, no login necessary: https://motherboard.vice.com/ ... pic.twitter.com/JEqIhLHLHJ
Context & Ripple Effects
This report fills a gap in the Equifax arc: the company wasn't just breached through an unpatched system — a researcher had flagged a public-facing site serving SSNs, names, and birthdates unencrypted in 2016, and Equifax sat on the fix for six months. That predates the breach itself and lands on top of findings that Equifax's strategy of hoarding personal data amplified the blast radius once attackers got in.
The pattern was already documented after the fact: the House report concluded subpar patching could have prevented the breach, and the GAO found information left vulnerable on many fronts. What's new here is a timestamped warning Equifax received before the intrusion — which converts 'security failure' into 'security failure despite notice,' and raises the liability question Motherboard's own editors flagged.
First-order effects
- Equifax's legal exposure sharpens immediately: a documented 2016 warning plus a six-month patch delay undercuts any 'we didn't know' defense and gives plaintiffs and investigators a concrete notice timeline.
- The researchers who reported the flaw — and Motherboard, publishing their account — shift the story from technical failure to governance failure, forcing Equifax to respond to questions about its vulnerability intake process rather than just its perimeter.
Second-order effects
- Regulators and congressional investigators gain a cleaner causal chain to work with: the House and GAO findings on missed patches now sit alongside evidence Equifax ignored a direct pre-breach report, strengthening the case for mandated disclosure and remediation timelines.
- Rival credit bureaus face pressure to prove they handle outside researcher reports differently, since the reputational damage here stems less from the flaw than from the six months of inaction after being told.
Third-order effects
- If the pattern holds, breach liability will hinge less on whether a company was hacked and more on whether it acted on warnings it received — making researcher disclosures and internal triage records central evidence in litigation and regulation.
- Data brokers whose business model is aggregating high-value identity data face a structural reckoning: the same hoarding that makes them targets also multiplies the cost of every unpatched endpoint, pushing toward regulatory minimums for handling sensitive-data exposure reports.
The trend: Major-breach accountability is shifting from 'was the system patched?' to 'did the company act on what it was told?', with pre-breach warnings becoming the decisive liability evidence.