Albuquerque Journal

Key Equifax executives departing in wake of massive data breach

Timeline of events released

- BY KEN SWEET

NEW YORK — Equifax announced late Friday that its chief technology officer and chief security officer would leave the company immediatel­y, following the enormous breach of 143 million Americans’ personal informatio­n.

The credit data company — under intense pressure since it disclosed last week that hackers accessed the Social Security numbers, birthdates and other informatio­n — also released a timeline of how it discovered and handled the breach.

Equifax said that Susan Mauldin, who had been the top security officer, and David Webb, the chief technology officer, are retiring. Mauldin, a college music major, had come under media scrutiny for her qualificat­ions in security. Equifax did not say in its statement what retirement packages the executives would receive.

Mauldin is being replaced by Russ Ayers, an informatio­n technology executive inside Equifax. Webb is being replaced by Mark Rohrwasser, who was in charge of Equifax’s internatio­nal technology operations.

Equifax also provided its most detailed timeline of the breach yet, although it raised as many questions as it answered.

The tale began on July 29, when the company’s security team detected suspicious network traffic associated with the software that ran its U.S. online-dispute portal. After blocking that traffic, the company saw additional “suspicious activity” and took the portal’s software offline.

At this point, events grow cloudy. Equifax said an internal review then “discovered” a flaw in an open-source software package called Apache Struts used in the dispute portal, which it then fixed with a software patch. It subsequent­ly brought the portal back online.

But that vulnerabil­ity had been known publicly since early March 2017, and a fix was available shortly thereafter — facts that Equifax acknowledg­ed in its Friday statement. The company did not say why the software used in the online-dispute portal hadn’t been patched earlier, although it claimed that its security organizati­on was “aware” of the software flaw in March.

After patching the dispute-portal’s software, Equifax hired Mandiant, a computer-security firm, to do a forensic review. That effort determined that hackers had access to Equifax systems from May 13 through July 30.

Equifax has been castigated for how it has handled the breach, which it did not disclose publicly for weeks after discoverin­g it.

Consumers calling the number Equifax set up initially complained of jammed phone lines and uninformed representa­tives, and initial responses from the website gave inconsiste­nt responses. Equifax also said Friday it would continue to allow people to place credit freezes on their reports without a fee through Nov. 21.

Equifax faces several inquiries and class-action lawsuits, including Congressio­nal investigat­ions, queries by the Federal Trade Commission and the Consumer Financial Protection Bureau. Three Equifax executives — not the ones who are departing — sold shares worth a combined $1.8 million just a few days after the company discovered the breach, according to documents filed with securities regulators.

 ?? ASSOCIATED PRESS ?? Equifax announced Friday that its chief technology offcier and chief security officer would retire after 143 million Americans’ personal informatio­n was stolen.
ASSOCIATED PRESS Equifax announced Friday that its chief technology offcier and chief security officer would retire after 143 million Americans’ personal informatio­n was stolen.

Newspapers in English

Newspapers from United States