Sources: two years before it was hacked, Equifax told the FBI of suspicions that company data including code and HR files may have been stolen by Chinese spies
The credit-reporting company went to the FBI with its suspicions—then the investigation stalled
Context & Ripple Effects
This report reframes the Equifax timeline: before the March 2017 discovery that eventually exposed records of some 143–150 million Americans, Equifax had already gone to the FBI suspecting that code and HR files were being siphoned by Chinese spies — and per the sources, that early investigation stalled rather than escalating.
The suspicion was later vindicated: Bloomberg reported within weeks of disclosure that investigators saw possible state sponsorship across 30+ entry points, and by February 2020 the DOJ charged four Chinese intelligence officers with the hack, with a subsequent court filing detailing how attribution was established.
First-order effects
- Equifax's two-year-old tip now reads as documented foreknowledge, sharpening scrutiny of both its internal handling of the intrusion and the executives whose post-discovery stock sales drew a separate DoJ probe.
- The FBI owns an uncomfortable question: a private company flagged suspected nation-state theft of source code and personnel files, and the investigation reportedly went nowhere until after the catastrophic breach.
Second-order effects
- Other US companies holding sensitive IP and employee data face pressure to treat pre-breach anomaly reports as national-security escalations rather than internal IT matters, since Equifax's tip became key attribution evidence.
- The stalled-probe account hands ammunition to critics of how federal agencies triage private-sector espionage warnings, likely fueling oversight questions about FBI resourcing and follow-through on corporate referrals.
Third-order effects
- If the pattern holds, corporate pre-incident reports become standing inputs to US indictments of foreign intelligence officers — turning routine corporate security telemetry into statecraft, as the DOJ charging strategy against Chinese hackers matures.
- Boards may come to treat suspected nation-state intrusion as a disclosure-level event with legal and diplomatic consequences, not merely a security incident, reshaping how enterprises document and escalate anomalies years before any public breach.
The trend: US responses to state-sponsored hacking are shifting from quiet corporate suspicion to public criminal attribution, with companies' earliest internal warnings becoming part of the official record.