It reads like a clean crime: silence, a payday, a penalty to match. Follow the paper and the clean story falls apart in three places at once.
Pairs with the Crisis Response Playbook — a ready-to-use strategy tool. Included in the Crisis Response Casebook →
On July 29, 2017, Equifax found the intruders inside its systems.2 The public would not hear a word about it until an SEC filing on September 7 — forty days later.1 In the interval, the company held one of the most sensitive datasets in America — the credit files behind about 147 million people3 — and said nothing while it worked out what had happened. That silence became the story. And the story hardened into a clean little crime: the company hid the breach for six weeks, cashed out its executives, paid its CEO for the cover-up, and got a $700 million fine to match. Every beat of that is memorable. Almost every beat is slightly off.
The official folk-memory version — Equifax stayed silent for six weeks, then its CEO got paid for hiding it, and regulators fined it $700 million for the delay — reads like justice. The record underneath is messier and, in a way, more useful: the gap was forty days, the CEO formally retired rather than being fired, and the $700 million was a ceiling for the underlying security failure, not a price tag on the wait.
The six weeks that were really forty days: the rounding sounds harmless, but it quietly reframes a disclosure window as a decision to hide
Start with the clock, because the whole moral of the story hangs on it. Equifax discovered the breach on July 29 and disclosed it on September 7 — a span of forty days, not a clean six weeks.21 The half-week the rounding adds is trivial arithmetically and enormous narratively. 'Six weeks of silence' implies a company that knew everything and sat on it. Forty days is closer to the awkward truth of any large breach: you find an intrusion before you understand its scope, and disclosing 'something happened, we don't yet know what' can be worse for consumers than disclosing a confirmed, scoped, remediated event. That doesn't make the delay defensible — a congressional investigation later called the breach 'entirely preventable' and faulted Equifax for having no clear lines of accountability for data security at all.7 But it does mean the sin was upstream. The company that couldn't secure the data in the first place was never going to have a crisp, fast story to tell about losing it.
Two stock sales the public folded into one: a cleared foursome and a charged individual became, in retelling, a single act of insider trading
The second beat — 'executives sold stock knowing about the breach' — is where the folk memory does its neatest sleight of hand, collapsing two entirely separate episodes into one villainy. Episode one: in early August, four senior executives, including the CFO, two division presidents, and the head of investor relations, sold roughly $1.8 million in stock.82 An Equifax special committee concluded they had not been told of the breach when they traded and cleared them, though the Justice Department ran its own probe.8 Episode two, and a different person entirely: Jun Ying, an executive next in line to be global CIO, exercised all his vested options and sold before disclosure — and the SEC charged him with insider trading, over proceeds of nearly $1 million, on the theory that he had inferred the breach on his own.5 Only Ying was charged. He wasn't one of the four in the headline stock-sale story. In the retelling, the charged man and the cleared foursome merged into a single boardroom cabal that never existed.
| The four senior executives | Jun Ying | |
|---|---|---|
| Roughly how much | ~$1.8M sold, collectively | ~$1M in proceeds |
| Knew of the breach? | Special committee found no — cleared | SEC alleged he inferred it himself |
| Outcome | No charges from the committee's finding | Charged by the SEC with insider trading |
| In the original headline? | Yes — the CFO and three others | No — a separate, lower-profile figure |
The CEO didn't get fired, and didn't get paid for silence: he retired, forfeited a bonus, and kept a fortune he'd already earned — a distinction that matters
The third and stickiest beat: the CEO got paid for the cover-up. Here the gap between memory and record is the widest. Richard Smith did not get fired. Equifax announced his departure as a retirement, effective September 26, 2017.6 As a condition, he 'irrevocably' forfeited his 2017 bonus — money that would normally have exceeded $3 million — but that was the extent of the immediate hit. He remained eligible for at least $18.4 million in pension benefits, and a calculation from Equifax's own securities filings put his total potential eventual payout, counting stock still set to vest, north of $90 million.6 Crucially, the company reserved the right to revisit 'any obligations or benefits owed' pending an independent board review.6 So the honest description is not 'paid for the cover-up.' It is: a CEO kept the pension and equity he had accrued over years, gave up one year's discretionary bonus, and had the rest left conditional. None of it was ever framed — by Equifax or by investigators — as compensation tied to the forty-day delay. It was the ordinary, galling machinery of an executive exit, not a bribe for silence.
What the $700 million was actually buying: a ceiling for a decade's worth of security failure, not a fine calibrated to a forty-day wait
And the fine. On July 22, 2019, the CFPB, the FTC, and 48 states plus D.C. and Puerto Rico entered a global settlement providing up to $700 million — the FTC's own announcement put the floor at at least $575 million.34 Read the structure and the point becomes obvious: up to $425 million in consumer monetary relief, a $100 million CFPB civil penalty, $300 million into a redress fund with $125 million more if needed, plus seven years of free credit reports.34 That is not the shape of a fine for being forty days late. It is the shape of a settlement over 'unfair and deceptive practices' spanning the entire incident that exposed 147 million people3 — the missing patch, the absent accountability, the years of underinvestment the House report catalogued.7 The delay is a footnote inside it. The '$700 million for the cover-up' framing takes a ceiling on a broad security-failure penalty and re-labels it a precise price for the one detail that's easiest to be angry about.
So here is the thesis, plainly: the Equifax morality tale punishes the wrong crime. It fixates on the forty-day silence because a delay is a discrete, dramatizable act — someone chose to wait — when the real failure was the diffuse, boring, years-long one of never securing the data or naming who owned that job.7 The delay is legible. The rot isn't. And a story that indicts the legible thing lets everyone feel the accounting is settled while the actual mechanism goes unexamined.
But doesn't the mess prove the guilt?: the fairest objection is that debunking the details risks excusing a genuinely inexcusable failure
The fair objection is that all this careful correction reads as a defense — that quibbling over forty days versus six weeks, or 'retired' versus 'fired,' or 'up to $700 million' versus a flat fine, is the sort of thing a company's crisis lawyers would love you to do while 147 million people had their identities exposed. It's a real objection, and the answer is that precision is not exoneration. Equifax's underlying conduct was, by a congressional finding, entirely preventable.7 The point of separating the beats is not to make the company sympathetic; it's that the popular version quietly lets the institution off the deeper hook. If you believe the whole scandal was a forty-day cover-up and a CEO bribe, then a company that discloses faster next time and skips the exit package has 'fixed' it. It hasn't. The thing that hurt 147 million people was the security failure the fast, angry story never touches. Getting the mechanism right is the only way to fine the right crime.
Every institutional failure gets compressed into the one act that's easiest to narrate — a delay, a stock sale, a golden parachute — because a discrete choice by a named person is dramatizable and a diffuse, years-long organizational rot is not. The trap is that the legible villain absorbs all the accountability, and once it's punished, everyone feels the ledger is balanced. Ask of any scandal: is the thing being prosecuted the thing that actually caused the harm? At Equifax the answer was no — the forty-day silence made headlines, but the missing patch and the absent line of accountability made the breach. When you find yourself furious at the cleanest detail, that's usually a sign the real failure is somewhere messier, and getting away with it.
Equifax will be remembered for forty days of silence and a CEO's parachute, because those are the parts of the story a person can hold in one hand. But the breach didn't happen in September; it happened over the years no one could say who owned the security of 147 million files.7 The delay was the symptom that made the news. The absence of an answer to 'whose job was this?' was the disease. Punish the delay and you've treated the fever. The thing that let it in is still in the building.
When the official story and the record disagree
Crisis Response Playbook
A playbook for a crisis already in motion: who decides, which plays fire on which trigger, and what gets said to whom. It replaces panic and the all-hands meeting with a pre-agreed sequence each person can run alone. Blank to pre-load before a crisis hits; filled as the worked example reconstructing the plays the story's team ran — and the ones they should have.
Included, filled and blank, in the Crisis Response Casebook. See the set → · Preview the blank →
Sources
Where this comes from — the filings, records, and reporting behind it.
- 1Equifax filed an 8-K with the SEC on September 7, 2017, disclosing that on that date it 'issued a press release providing important information regarding a cybersecurity incident involving access to certain consumer information.'
- 2The breach occurred between mid-May and July 2017 and was discovered by Equifax on July 29, 2017, roughly six weeks before the company's September 7, 2017 public disclosure; Bloomberg's contemporaneous reporting confirms senior executives traded stock in the days after the company 'discovered a security breach' but before it was publicly revealed on September 7.
- 3On July 22, 2019, the CFPB, FTC, and 48 states, D.C., and Puerto Rico entered a global settlement — via complaint and stipulated judgment in federal district court in the Northern District of Georgia — providing up to $700 million in relief and penalties, including up to $425 million in consumer monetary relief and a $100 million CFPB civil money penalty, over unfair and deceptive practices tied to the 2017 breach affecting about 147 million consumers.
- 4The FTC's parallel settlement announcement states Equifax agreed to pay at least $575 million, and potentially up to $700 million, with $300 million placed into a consumer redress fund (plus up to $125 million more if needed) and additional consumer protections including free credit reports for seven years.
- 5The SEC charged former Equifax executive Jun Ying, who was next in line to be global CIO, with insider trading for exercising all his vested Equifax stock options and selling the shares before the public breach disclosure, reaping proceeds of nearly $1 million and avoiding more than $117,000 in losses.
- 6Equifax announced CEO Richard Smith's retirement effective September 26, 2017; as a condition, he 'irrevocably' forfeited his 2017 bonus (which would normally have totaled more than $3 million), but he remained eligible for at least $18.4 million in pension benefits, and Fortune's calculation based on Equifax securities filings put his total potential eventual payout — including vesting stock — at more than $90 million; Equifax also stated it reserved the right to revisit 'any obligations or benefits owed' pending an independent board review of the breach.
- 7A House Oversight and Government Reform Committee staff report, following a 14-month investigation reviewing over 122,000 pages of documents, concluded the breach was 'entirely preventable' and that Equifax failed to fully appreciate and mitigate its cybersecurity risks, and failed to implement clear lines of accountability and management structure for data security.
- 8An Equifax special committee investigation concluded that four executives — CFO John Gamble, U.S. Information Solutions president Joseph Loughran, Workforce Solutions president Rodolfo Ploder, and Investor Relations SVP Douglas Brandberg — who together sold about $1.8 million in stock before the breach was disclosed, traded appropriately and were not aware of the breach at the time, though the Department of Justice conducted its own separate probe of the trades.
More like this — beyond Equifax
New Strategically analyses as they publish: the defining moves in business, checked against the record. No noise, and one click to leave.