Equifax has confirmed that attackers breached its systems by exploiting a flaw in Apache Struts, CVE-2017-5638, that Apache fixed via a March software update. At the time of Equifax’s mid-May breach, however, the credit bureau had not yet upgraded to the newer, patched version of the software. The credit bureau has yet to divulge many facts about the massive data breach it suffered, including who hacked the data bureau, how many individuals – beyond 143 million U.S. adults – were impacted.”]
Source: https://www.careersinfosecurity.com/unpatched-apache-struts-flaw-to-blame-for-equifax-hack-a-10285