Former Equifax chairman apologizes for data breach

Image
AP Washington
Last Updated : Oct 02 2017 | 11:22 PM IST
The former chairman and CEO of Equifax says the company was entrusted with personal information of 140 million Americans and "we let them down" as human error and technology failures allowed a massive data breach.
In prepared congressional testimony, Richard F Smith said the millions are not just numbers in a database, but friends, family, neighbors and members of his church. The revelation last month of the disastrous hack to Equifax's computer system rocked the company which faces several state and federal inquiries and a myriad of class-action lawsuits.
"To each and every person affected by this breach, I am deeply sorry that this occurred. Whether your personal identifying information was compromised, or you have had to deal with the uncertainty of determining whether or not your personal data may have been compromised, I sincerely apologize," Smith said. "The company failed to prevent sensitive information from falling into the hands of wrongdoers."
Smith, who resigned after overseeing the company for a dozen years, says Equifax was hacked by a yet-unknown entity. He said the information stolen included names, Social Security numbers, birth dates and addresses. In addition, the credit card information for about 209,000 consumers was also stolen as well as certain documents with personally identifying information for approximately 182,000 consumers.
Lawmakers are expected to question Smith on how the company allowed the breach to occur, why it took as long as it did to notify consumers and what's it's doing to help consumers protect themselves going forward. The House subcommittee holding the hearing has jurisdiction over e- commerce and consumer protection issues.
Smith said the Department of Homeland Security warned the company on March 8 about the need to patch a particular vulnerability in software used by Equifax and other business.
The company disseminated that warning by email the next day and requested that applicable personnel install the upgrade. The company's policy requires the upgrade to occur within 48 hours, but Smith said that did not occur. The company's information security department also ran scans on March 15 that did not pick up the vulnerability.
"I understand that Equifax's investigation into these issues is ongoing," Smith said in the prepared remarks. "The company knows, however, that it was this unpatched vulnerability that allowed hackers to access personal identifying information.

Disclaimer: No Business Standard Journalist was involved in creation of this content

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Oct 02 2017 | 11:22 PM IST

Next Story