Claiming that Efx failed to patch in March is a falsehood, motive undetermined.
From Efx's Sept bulletin:
"The particular vulnerability in Apache Struts was identified and disclosed by U.S. CERT in early March 2017.
Equifax’s Security organization was aware of this vulnerability at that time...