They didn't. Pension plans and individual investors are not sophisticated financial organizations. They rely on those that are to do their job in a non-fraudulent manner. They didn't.
Equifax is just as shady as those lenders - more so IMO because they have absolutely no obligation or business relationship directly with the individual's whose private data they compromised.
Why am I supposed to take it as a given that if these organizations use the info it must be useful, then?