Lawmakers grill former Equifax chairman over data breach


House Republicans and Democrats on Tuesday grilled Equifax's former chief executive over the massive data hack of the personal information of 145 million Americans, calling the company's response inadequate as consumers struggle to deal with the breach.

Former Equifax CEO Richard Smith apologized for the compromise of such information as names, addresses, birth dates and Social Security numbers. Smith was the lone witness at the first of several Capitol Hill hearings this week. No current Equifax official testified.

"The criminal hack happened on my watch, and as CEO, I am ultimately responsible, and I take full responsibility," Smith said. "I am here today to say to each and every person affected by this breach, I am truly and deeply sorry for what happened."

Democrats favor legislation that they say would establish strong data security standards and prompt notification and relief for consumers when their information is hacked. But Republicans tamped down expectations for any congressional action as this year the GOP-led Congress has rolled back several Obama-era rules affecting businesses and the financial sector.

"Equifax deserves to be shamed in this hearing, but we should also ask what Congress has done, or failed to do, to stop data breaches from occurring," said Rep. Jan Schakowsky, D-Ill.

Rep. Bob Latta, R-Ohio, the chairman of the subcommittee examining the breach, said there are already laws on the books that require companies to secure sensitive consumer data. He said that hearings before four House and Senate panels this week should run their course before lawmakers make a decision about what to do next.

"The big thing we heard today is it was a very human error on their part" Latta said.

Smith offered a timeline of what went wrong, saying the Department of Homeland Security warned the company on March 8 about the need to patch a particular vulnerability in software used by Equifax and other businesses. The company disseminated that warning by email the next day and requested that applicable personnel install the upgrade. The company's policy requires the upgrade to occur within 48 hours, but that did not occur. The company's information security department also ran scans on March 15 that did not pick up the vulnerability.

In late July, data security officials noticed suspicious activity on a website, which Smith said "happens routinely around our business." He said an internal investigation ensued and he was alerted the next day, but he had no knowledge at that time that consumers' personal information had been accessed.

Lawmakers pressed Smith about company executives selling stock in the company after the suspicious activity had been detected. On Aug. 1 and 2, Equifax Chief Financial Officer John Gamble and two other executives, Rodolfo Ploder and Joseph Loughran, sold a combined $1.8 million in stock.

Smith described the executives as "honorable men, men of integrity." He said at that point in time the company was unaware that consumer data had been accessed.

Schakowsky said "for a lot of Americans, that just doesn't pass the smell test."

Smith said the full extent of what occurred emerged during a meeting he had with cybersecurity experts and outside counsel on August 17. The board was alerted the following week and the public on Sept. 7, after the company had made plans for how it would try to help consumers respond.

The timeline laid out by Smith didn't satisfy many lawmakers, who accused the company of being too slow.

"I worry that your job today is about damage control. You put a happy face on your firm's disgraceful actions, and then depart with a golden parachute," said Ben Ray Lujan, D-N.M. "Unfortunately, if fraudsters destroy my constituent's savings and financial futures, there's no golden parachute awaiting them."

Lawmakers said that at one point Equifax tweeted the wrong link for consumers to check to learn if they were part of the breach.

"Talk about ham-handed responses, this is simply unacceptable," said Rep. Greg Walden, R-Ore.

Smith said he was disappointed in the rollout of call centers and a website designed to help the people affected by the breach. He said the company has increased its number of customer service representatives and the website has been improved. He said more than 400 million consumers contacted the company in the weeks following the announcement of the breach. He said the company wasn't prepared for that kind of volume.

Lawmakers said they're getting scores of calls from constituents concerned that their information was stolen and the potential ramifications in the years ahead. Rep. Ryan Costello, R-Pa., said hundreds of constituents have contacted his office about the company's response.

"The slow rollout and how poorly it was done. To me, it was just inexcusable," Costello said.

___

Follow Kevin Freking on Twitter at https://twitter.com/APkfreking


Reader Comments ...


Next Up in Nation & World

Atlanta police sergeant awarded $100,000 after false DUI arrest in suburban county
Atlanta police sergeant awarded $100,000 after false DUI arrest in suburban county

An Atlanta police sergeant was awarded more than $100,000 of Forsyth County taxpayer money after a lawsuit was settled last week because he was erroneously arrested for a DUI, WSB-TV reported.  >> Read more trending news  In August 2017, Sgt. Paul Sparwath called 911 when he saw some teenagers acting suspiciously in his Forsyth County...
There have been 3 workplace shootings in 24 hours
There have been 3 workplace shootings in 24 hours

Three workplace shootings in three different states in a 24-hour period are putting American workers on edge. It seems it can happen anywhere these days and it does. >> Read more trending news  On Wednesday morning, a 43-year-old man showed up at the software company where he works outside Madison, Wisconsin, and opened fire. Four people...
Delta to launch facial recognition at check-in, boarding and other terminal locations
Delta to launch facial recognition at check-in, boarding and other terminal locations

Delta Air Lines plans to launch what it calls the nation’s first “biometric terminal” by deploying facial recognition at multiple points in the international terminal at Hartsfield-Jackson. At the Maynard H. Jackson International Terminal and Concourse F at the Atlanta airport, Delta plans to use facial recognition at check-in...
Aberdeen shooting: Woman, 26, kills self, 3 others in 'horrific' Rite Aid center incident
Aberdeen shooting: Woman, 26, kills self, 3 others in 'horrific' Rite Aid center incident

Four people died Thursday after a temporary employee opened fire at a Rite Aid distribution center in Maryland, according to Harford County sheriff’s deputies. The suspected shooter was among the deceased, Sheriff Jeffrey Gahler said. Deputies in Harford County said they responded just after 9 a.m. to reports of a shooting with “multiple...
9-year-old girl dies from Type 1 diabetes after blood sugar drop during sleepover
9-year-old girl dies from Type 1 diabetes after blood sugar drop during sleepover

A small-town community in Lawrence County, Pennsylvania is dealing with a huge loss. >> Read more trending news  Sophia Daugherty, 9, a fifth-grader at Laurel Elementary School, died Wednesday from complications of Type 1 diabetes. Her family said she suffered an extreme blood sugar drop during a sleepover last weekend and was found...
More Stories