It reads like a clean crime: silence, a payday, a penalty to match. Follow the paper and the clean story falls apart in three places at once.

Pairs with the Crisis Response Playbook — a ready-to-use strategy tool. Included in the Crisis Response Casebook →

On July 29, 2017, Equifax found the intruders inside its systems.2 The public would not hear a word about it until an SEC filing on September 7 — forty days later.1 In the interval, the company held one of the most sensitive datasets in America — the credit files behind about 147 million people3 — and said nothing while it worked out what had happened. That silence became the story. And the story hardened into a clean little crime: the company hid the breach for six weeks, cashed out its executives, paid its CEO for the cover-up, and got a $700 million fine to match. Every beat of that is memorable. Almost every beat is slightly off.

The official folk-memory version — Equifax stayed silent for six weeks, then its CEO got paid for hiding it, and regulators fined it $700 million for the delay — reads like justice. The record underneath is messier and, in a way, more useful: the gap was forty days, the CEO formally retired rather than being fired, and the $700 million was a ceiling for the underlying security failure, not a price tag on the wait.

The Equifax breach — the numbers people compress
July 29, 2017
Breach discovered by Equifax2
Sept 7, 2017
Public disclosure via SEC 8-K1
~147M
Consumers affected3
Up to $700M
Ceiling of the 2019 settlement3

The six weeks that were really forty days: the rounding sounds harmless, but it quietly reframes a disclosure window as a decision to hide

Start with the clock, because the whole moral of the story hangs on it. Equifax discovered the breach on July 29 and disclosed it on September 7 — a span of forty days, not a clean six weeks.21 The half-week the rounding adds is trivial arithmetically and enormous narratively. 'Six weeks of silence' implies a company that knew everything and sat on it. Forty days is closer to the awkward truth of any large breach: you find an intrusion before you understand its scope, and disclosing 'something happened, we don't yet know what' can be worse for consumers than disclosing a confirmed, scoped, remediated event. That doesn't make the delay defensible — a congressional investigation later called the breach 'entirely preventable' and faulted Equifax for having no clear lines of accountability for data security at all.7 But it does mean the sin was upstream. The company that couldn't secure the data in the first place was never going to have a crisp, fast story to tell about losing it.

Two stock sales the public folded into one: a cleared foursome and a charged individual became, in retelling, a single act of insider trading

The second beat — 'executives sold stock knowing about the breach' — is where the folk memory does its neatest sleight of hand, collapsing two entirely separate episodes into one villainy. Episode one: in early August, four senior executives, including the CFO, two division presidents, and the head of investor relations, sold roughly $1.8 million in stock.82 An Equifax special committee concluded they had not been told of the breach when they traded and cleared them, though the Justice Department ran its own probe.8 Episode two, and a different person entirely: Jun Ying, an executive next in line to be global CIO, exercised all his vested options and sold before disclosure — and the SEC charged him with insider trading, over proceeds of nearly $1 million, on the theory that he had inferred the breach on his own.5 Only Ying was charged. He wasn't one of the four in the headline stock-sale story. In the retelling, the charged man and the cleared foursome merged into a single boardroom cabal that never existed.

The four senior executivesJun Ying
Roughly how much~$1.8M sold, collectively~$1M in proceeds
Knew of the breach?Special committee found no — clearedSEC alleged he inferred it himself
OutcomeNo charges from the committee's findingCharged by the SEC with insider trading
In the original headline?Yes — the CFO and three othersNo — a separate, lower-profile figure
The two stock-sale episodes, kept apart

The CEO didn't get fired, and didn't get paid for silence: he retired, forfeited a bonus, and kept a fortune he'd already earned — a distinction that matters

The third and stickiest beat: the CEO got paid for the cover-up. Here the gap between memory and record is the widest. Richard Smith did not get fired. Equifax announced his departure as a retirement, effective September 26, 2017.6 As a condition, he 'irrevocably' forfeited his 2017 bonus — money that would normally have exceeded $3 million — but that was the extent of the immediate hit. He remained eligible for at least $18.4 million in pension benefits, and a calculation from Equifax's own securities filings put his total potential eventual payout, counting stock still set to vest, north of $90 million.6 Crucially, the company reserved the right to revisit 'any obligations or benefits owed' pending an independent board review.6 So the honest description is not 'paid for the cover-up.' It is: a CEO kept the pension and equity he had accrued over years, gave up one year's discretionary bonus, and had the rest left conditional. None of it was ever framed — by Equifax or by investigators — as compensation tied to the forty-day delay. It was the ordinary, galling machinery of an executive exit, not a bribe for silence.

$18.4M
the pension Smith kept — earned over years, not a payout for the delay — while forfeiting only his up-to-$3M annual bonus6

What the $700 million was actually buying: a ceiling for a decade's worth of security failure, not a fine calibrated to a forty-day wait

And the fine. On July 22, 2019, the CFPB, the FTC, and 48 states plus D.C. and Puerto Rico entered a global settlement providing up to $700 million — the FTC's own announcement put the floor at at least $575 million.34 Read the structure and the point becomes obvious: up to $425 million in consumer monetary relief, a $100 million CFPB civil penalty, $300 million into a redress fund with $125 million more if needed, plus seven years of free credit reports.34 That is not the shape of a fine for being forty days late. It is the shape of a settlement over 'unfair and deceptive practices' spanning the entire incident that exposed 147 million people3 — the missing patch, the absent accountability, the years of underinvestment the House report catalogued.7 The delay is a footnote inside it. The '$700 million for the cover-up' framing takes a ceiling on a broad security-failure penalty and re-labels it a precise price for the one detail that's easiest to be angry about.

So here is the thesis, plainly: the Equifax morality tale punishes the wrong crime. It fixates on the forty-day silence because a delay is a discrete, dramatizable act — someone chose to wait — when the real failure was the diffuse, boring, years-long one of never securing the data or naming who owned that job.7 The delay is legible. The rot isn't. And a story that indicts the legible thing lets everyone feel the accounting is settled while the actual mechanism goes unexamined.

But doesn't the mess prove the guilt?: the fairest objection is that debunking the details risks excusing a genuinely inexcusable failure

The fair objection is that all this careful correction reads as a defense — that quibbling over forty days versus six weeks, or 'retired' versus 'fired,' or 'up to $700 million' versus a flat fine, is the sort of thing a company's crisis lawyers would love you to do while 147 million people had their identities exposed. It's a real objection, and the answer is that precision is not exoneration. Equifax's underlying conduct was, by a congressional finding, entirely preventable.7 The point of separating the beats is not to make the company sympathetic; it's that the popular version quietly lets the institution off the deeper hook. If you believe the whole scandal was a forty-day cover-up and a CEO bribe, then a company that discloses faster next time and skips the exit package has 'fixed' it. It hasn't. The thing that hurt 147 million people was the security failure the fast, angry story never touches. Getting the mechanism right is the only way to fine the right crime.

Beware the crisis with a legible villain

Every institutional failure gets compressed into the one act that's easiest to narrate — a delay, a stock sale, a golden parachute — because a discrete choice by a named person is dramatizable and a diffuse, years-long organizational rot is not. The trap is that the legible villain absorbs all the accountability, and once it's punished, everyone feels the ledger is balanced. Ask of any scandal: is the thing being prosecuted the thing that actually caused the harm? At Equifax the answer was no — the forty-day silence made headlines, but the missing patch and the absent line of accountability made the breach. When you find yourself furious at the cleanest detail, that's usually a sign the real failure is somewhere messier, and getting away with it.

Equifax will be remembered for forty days of silence and a CEO's parachute, because those are the parts of the story a person can hold in one hand. But the breach didn't happen in September; it happened over the years no one could say who owned the security of 147 million files.7 The delay was the symptom that made the news. The absence of an answer to 'whose job was this?' was the disease. Punish the delay and you've treated the fever. The thing that let it in is still in the building.

Take it with you — Crisis Response
Playbook

Crisis Response Playbook

A playbook for a crisis already in motion: who decides, which plays fire on which trigger, and what gets said to whom. It replaces panic and the all-hands meeting with a pre-agreed sequence each person can run alone. Blank to pre-load before a crisis hits; filled as the worked example reconstructing the plays the story's team ran — and the ones they should have.

Blank template

Included, filled and blank, in the Crisis Response Casebook. See the set → · Preview the blank →

Sources

Where this comes from — the filings, records, and reporting behind it.

  1. 1
    Primary · SEC filingDocumented
    Equifax filed an 8-K with the SEC on September 7, 2017, disclosing that on that date it 'issued a press release providing important information regarding a cybersecurity incident involving access to certain consumer information.'
  2. 2
    PublishedWidely reported
    The breach occurred between mid-May and July 2017 and was discovered by Equifax on July 29, 2017, roughly six weeks before the company's September 7, 2017 public disclosure; Bloomberg's contemporaneous reporting confirms senior executives traded stock in the days after the company 'discovered a security breach' but before it was publicly revealed on September 7.
  3. 3
    Primary · Court recordDocumented
    On July 22, 2019, the CFPB, FTC, and 48 states, D.C., and Puerto Rico entered a global settlement — via complaint and stipulated judgment in federal district court in the Northern District of Georgia — providing up to $700 million in relief and penalties, including up to $425 million in consumer monetary relief and a $100 million CFPB civil money penalty, over unfair and deceptive practices tied to the 2017 breach affecting about 147 million consumers.
  4. 4
    Primary · Court recordDocumented
    The FTC's parallel settlement announcement states Equifax agreed to pay at least $575 million, and potentially up to $700 million, with $300 million placed into a consumer redress fund (plus up to $125 million more if needed) and additional consumer protections including free credit reports for seven years.
  5. 5
    Primary · SEC filingDocumented
    The SEC charged former Equifax executive Jun Ying, who was next in line to be global CIO, with insider trading for exercising all his vested Equifax stock options and selling the shares before the public breach disclosure, reaping proceeds of nearly $1 million and avoiding more than $117,000 in losses.
  6. 6
    PublishedWidely reported
    Equifax announced CEO Richard Smith's retirement effective September 26, 2017; as a condition, he 'irrevocably' forfeited his 2017 bonus (which would normally have totaled more than $3 million), but he remained eligible for at least $18.4 million in pension benefits, and Fortune's calculation based on Equifax securities filings put his total potential eventual payout — including vesting stock — at more than $90 million; Equifax also stated it reserved the right to revisit 'any obligations or benefits owed' pending an independent board review of the breach.
  7. 7
    Primary · ArchivalDocumented
    A House Oversight and Government Reform Committee staff report, following a 14-month investigation reviewing over 122,000 pages of documents, concluded the breach was 'entirely preventable' and that Equifax failed to fully appreciate and mitigate its cybersecurity risks, and failed to implement clear lines of accountability and management structure for data security.
  8. 8
    PublishedAttributed to source
    An Equifax special committee investigation concluded that four executives — CFO John Gamble, U.S. Information Solutions president Joseph Loughran, Workforce Solutions president Rodolfo Ploder, and Investor Relations SVP Douglas Brandberg — who together sold about $1.8 million in stock before the breach was disclosed, traded appropriately and were not aware of the breach at the time, though the Department of Justice conducted its own separate probe of the trades.

More like this — beyond Equifax

New Strategically analyses as they publish: the defining moves in business, checked against the record. No noise, and one click to leave.