This logic makes no sense to me. You have a company that stores, without consent, highly personal data for almost every American. There was an implied responsibility to protect that information. For such a company, security should be pretty high on the priority list. All of the following is negligence:
1) Store all this information, unencrypted
2) They were told of the vulnerability in March and had 2 months to update the software.
3) Afterwards, set up a broken website with a DV certificate to accept SSN numbers.
4) The website, even though was a vulnerability disclosure, tried to _sell_ an Equifax identity monitoring package.
5) Redirect your own customers to a phishing website set up by a white hat hacker
6) Allow employees to have usernames/pws like 'admin/admin' on edge servers
The circumstances that led to the vulnerability, and the actions that Equifax took afterwards absolutely warrant outrage. And this is not even taking into account the original point - this is a pattern of incompetence and failure - but to add to the fire, Equifax was a company that was tasked with storing highly sensitive personal data for millions of Americans and did not take the appropriate security steps to do so; in fact, they ignored even the most basic security measures. They should have had at least bank-level security with such a responsibility. There is no excuse.