Houston Chronicle

Equifax to pay up to $700 million to settle massive 2017 data breach

- By Tony Romm

Equifax has agreed to pay as much as $700 million to settle a series of state and federal investigat­ions into a massive 2017 data breach that left more than 147 million Americans’ Social Security numbers, creditcard details and other sensitive informatio­n exposed.

The punishment includes payments to affected consumers, fines to peeved regulators and a host of required changes to the credit-reporting agency’s business practices, government officials said Monday, as they faulted Equifax for putting more than half of all U.S. adults at risk for identity theft and fraud.

“This is the largest data breach settlement in U.S. history,” said Pennsylvan­ia Attorney General Josh Shapiro. “These data breaches occur because of corporate greed. Corporate leaders decided to put an extra dollar of profit into their pocket, as opposed to that dollar going into the infrastruc­ture of the company to protect their data.”

Under an agreement with the attorneys general from 48 states as well as the District of Columbia and Puerto Rico, Equifax will set aside up to $425 million to reimburse victims of the breach, including those who experience­d identity theft. Equifax also will offer 10 years of credit-monitoring services to consumers who have been harmed, invest more heavily in its own cybersecur­ity and pay $175 million to the states themselves, officials said. They described the penalty as the most significan­t they’ve ever levied in response to an organizati­on that broke state data-security laws.

Equifax also has agreed to pay an additional $100 million to settle a federal investigat­ion at the Consumer Financial Protection Bureau, the agency said Monday. The Federal Trade Commission, meanwhile, is requiring the company to implement a new security program and submit to 20 years of regular, third-party checkups. Future security mishaps that violate the settlement could lead to additional fines from the agency.

“This settlement requires that the company take steps to improve its data security going forward, and will ensure that consumers harmed by this breach can receive help protecting themselves from identity theft and fraud,” said FTC Chairman Joe Simons in a statement.

In response, Mark W. Begor, the chief executive of Equifax, touted cybersecur­ity improvemen­ts it made after the breach. “The consumer fund of up to $425 million that we are announcing today reinforces our commitment to putting consumers first and safeguardi­ng their data — and reflects the seriousnes­s with which we take this matter,” he said in a statement.

The Equifax breach, which the credit-reporting agency first acknowledg­ed in September 2017, amounted to one of the worst security incidents in U.S. history given the number of Americans affected and the sensitivit­y of the informatio­n that hackers were able to access. Names, home addresses and birth dates were left exposed, and in some cases, Americans’ driver’s license numbers were left vulnerable to theft, too.

The breach enraged lawmakers, regulators and victims because Equifax, as one of the country’s three major credit reporting bureaus, plays a central role in determinin­g Americans’ financial futures — from whether a person can obtain credit to the interest rate they pay on their mortgage. Yet Equifax still failed to adopt even the most elementary cybersecur­ity protection­s, putting Americans’ financial livelihood­s at risk.

For years, many of Equifax’s sensitive computer systems had not been patched against known digital vulnerabil­ities, according to state, federal and congressio­nal investigat­ors, who began issuing their findings earlier this year. More than 8,500 security fixes, or patches, never were made to known vulnerabil­ities as far back as 2015, defying industry-best practices, lawmakers found.

Some of the most sensitive data Equifax housed — including Americans’ Social Security numbers — had been stored in plain text, according to the FTC, making that informatio­n vulnerable to theft and abuse. When the breach occurred in 2017, it took Equifax 76 days just to discover it, despite the fact that it had been wellaware of a major vulnerabil­ity in its computer systems months before the incident, state and federal officials said Monday.

For two years, Democrats and Republican­s on Capitol Hill lashed Equifax executives at a series of hearings. Its chief executive at the time quickly resigned. Other Equifax executives soon found themselves in their own legal trouble: The Justice Department later determined that the credit reporting agency’s chief informatio­n officer sold his stock in advance of Equifax’s official announceme­nt. The executive, Jun Ying, was sentenced for insider trading, making him the second Equifax official to be found guilty of such charges.

“This company’s ineptitude, negligence and lax security standards endangered the identities of half the U.S. population,” said New York Attorney General Letitia James. “Now it’s time for the company to do what’s right and not only pay restitutio­n to the millions of victims of their data breach, but also provide every American who had their highly sensitive informatio­n accessed with the tools they need to battle identity theft in the future.”

 ?? Mike Stewart / Associated Press ?? Equifax will set aside up to $425 million to reimburse victims of the 2017 data breach that exposed Social Security numbers and other private informatio­n of nearly 150 million people.
Mike Stewart / Associated Press Equifax will set aside up to $425 million to reimburse victims of the 2017 data breach that exposed Social Security numbers and other private informatio­n of nearly 150 million people.
 ??  ?? Begor
Begor

Newspapers in English

Newspapers from United States