Chattanooga Times Free Press

Equifax CEO steps down in the wake of data breach

Smith could walk away with $18 million

- BY KEN SWEET AND MICHAEL LIEDTKE

Equifax CEO Richard Smith stepped down Tuesday, less than three weeks after the credit reporting agency disclosed a damaging hack to its computer system that exposed highly sensitive informatio­n for about 143 million Americans.

His departure follows those of two other high-ranking executives who left in the wake of the hack, which exploited a software flaw the company did not fix to expose Social Security numbers, birthdates and other personal data that provide the keys to identify theft.

Smith, who had been CEO since 2005, also will leave the chairman post.

Equifax said Smith was retiring, but he will not receive his annual bonus and other potential retirement-related benefits until the company’s board concludes an independen­t review of the data breach. If the review does not find Smith at fault, he could walk away with a retirement package of at least $18.48 million, with the value of the stock and options he was paid out over his 12-year tenure. The board also could “claw back” any cash or stock bonuses he may have received, if necessary.

Smith, 57, who made almost $15 million in salary, bonuses and stock last year, will be able to stay on the company’s health plan for life.

Paulino do Rego Barros Jr., most recently president of the Asia Pacific region, was named interim CEO. Board member Mark Feidler was appointed nonexecuti­ve chairman. Equifax said it will look both inside and outside the company for a permanent CEO.

Even with the departures of three top executives, Equifax is still facing several inquiries and class-action lawsuits, including congressio­nal investigat­ions, queries by the Federal Trade Commission and the Consumer Financial Protection Bureau, as well as several state attorneys general.

Three other executives were found to have sold stock for a combined $1.8 million before Equifax disclosed the most serious breach, though the company says they were unaware of it at the time.

Although analysts previously had applauded Equifax’s performanc­e under Smith, he and his management team came under fire for lax security and their response to the breach. Confusion over the terms of credit-monitoring protection and jammed phone lines added to people’s ire. The company’s stock has lost a third of its value — a $5.5 billion setback.

Equifax’s board clearly needed to dump Smith, not only as a public show of penance for the breach but also for the company’s bungling since informing consumers their identities are in danger of being stolen, said Bart Friedman, a lawyer specializi­ng in corporate governance issues for Cahill Gordon and Reindel.

“This was like a fivealarm fire and the lack of an appropriat­e response by management just poured gasoline on that fire,” Friedman said. “If you are sitting on that board, I don’t know how you could have permitted him to stay in his role. I have rarely seen such a botched response to an existentia­l threat.”

Equifax tried to appease incensed lawmakers, consumers and investors by announcing the unceremoni­ous retirement of its chief security officer and chief informatio­n officer, who were responsibl­e for managing and protecting the company’s technology. But that wasn’t enough, with lawmakers drawing up bills that would impose sweeping reforms on Equifax and its two main rivals, Experian and TransUnion.

Smith had been scheduled to appear at two congressio­nal hearings next week that would likely have turned into a public lambasting. The House Energy and Commerce committee said in a tweet that it still plans to hold its hearing Oct. 3. A member of the Senate Banking Committee said he still wanted Smith to appear Oct. 4 as planned.

“A CEO walking out the door just days before he is to appear before Congress is an abdication of his responsibi­lity. This company has jeopardize­d the financial health and security of 143 million people, and they need to be held responsibl­e. So I fully expect Mr. Smith to testify before the Banking Committee next week, regardless of the timing of his retirement,” said Sen. Brian Schatz, a Democrat from Hawaii.

The data breach might not have happened if Equifax had responded promptly to a March warning about a known security weakness in a piece of open-source software called Apache Struts. Even though a repair was released, Equifax did not immediatel­y install it. Digital burglars used the crack in Equifax’s computer systems to break in from May 13 through July 30, according to the company’s accounting.

Equifax said it did not fathom the breadth of informatio­n that had been stolen until shortly before issuing a public alert on Sept. 7, triggering the wave of withering condemnati­ons that led to Smith’s departure.

The jobs of other Equifax executives could still be in jeopardy. The three who sold shares, including Equifax’s chief financial officer, are under scrutiny.

In a hearing Tuesday, the chairman of the Securities and Exchange Commission, Jay Clayton, refused to comment when asked by lawmakers if executives at Equifax engaged in insider trading when they sold their shares. He did not confirm or deny that the SEC was investigat­ing the issue.

 ?? ASSOCIATED PRESS FILE PHOTO ?? The Equifax Inc. headquarte­rs is seen in Atlanta. On Tuesday credit reporting agency Equifax ousted CEO Richard Smith in an effort to clean up the mess left by a damaging data breach.
ASSOCIATED PRESS FILE PHOTO The Equifax Inc. headquarte­rs is seen in Atlanta. On Tuesday credit reporting agency Equifax ousted CEO Richard Smith in an effort to clean up the mess left by a damaging data breach.
 ??  ?? Richard Smith
Richard Smith

Newspapers in English

Newspapers from United States