Yeah, that phrase in the article is clearly wrong. What the report actually says is that the Equifax ACIS application (Automated Consumer Interview System) was originally developed in the 1970s. Obviously it has changed since then, since at the time of the breach it was using Apache Struts.

The report cites an interview with Graeme Payne, Equifax manager of the ACIS system, stating that when he joined the firm in 2014 they were still running ACIS on the original platform (more or less), but then goes on to say that it was running on Sun servers, so obviously he wasn't too clear on the history either.

My guess is that the Struts-using, post-2014 incarnation of ACIS was at least the third platform for it.

