I have a different question. So here's their timeline:
MARCH 2017 - Vuln in Struts is disclosed by CERT.
MAY 13 - Initial intrusion happens according to FireEye's later analysis
JULY 29 - Equifax notices weird activity.
JULY 30 - Equifax notices more weird activity.
JULY 30 - Equifax takes down affected web site
JULY 30ish? - Equifax realized vuln was Struts. Patches. Puts site right back up.
AUG 2 - Hire FireEye to check things out
(weeks) - FireEye assesses situation and presumably Equifax panics
SEP 7 - Equifax makes intrusion public, offers self-described "comprehensive package" including the web site "so that consumers can quickly and easily find the information they need".
At SOME point, they kind of shove in the statement that following entities were notified:
* FBI
* all U.S. State Attorneys General
* other federal regulators.
My question is WHEN did this happen? It's my understanding there are rules-- state and federal-- about when law enforcement (and affected parties) need to be notified on a breach of this size involving this type of sensitive information.
Anyone have more insight on this?