This document provides a case study analysis of the 2017 Equifax data breach which compromised the personal information of 148 million US citizens. Key factors that contributed to the breach included Equifax failing to patch its systems for a known vulnerability (Apache Struts CVE-2017-5638) despite being notified by multiple organizations. Equifax also mishandled its response to the breach, directing victims to fake settlement sites and using easily guessable PINs, drawing widespread criticism. The breach highlighted issues with credit reporting agencies and incident response processes.