116 3rd St SE
Cedar Rapids, Iowa 52401
Ex-Equifax CEO to apologize in congressional testimony for data breach
Los Angeles Times
Oct. 2, 2017 9:46 pm
WASHINGTON - The former chief executive of Equifax plans to apologize for the credit reporting company's massive data breach when he testifies Tuesday before a congressional committee, as well as detail the missteps in response to the hack that exposed the Social Security numbers and birth dates of as many as 143 million people.
'Equifax was entrusted with Americans' private data and we let them down,” Richard Smith said in written testimony for the hearing that the House Energy and Commerce Committee released Monday. 'To each and every person affected by this breach, I am deeply sorry that this occurred.”
Smith stepped down last week in the wake of the breach, which has sparked numerous federal and state investigations as well as outrage from lawmakers.
His appearance Tuesday before the House panel will be the first of three before congressional committees this week.
In his written testimony, Smith blamed the breach on 'human error and technology failures” and said the company was a victim of 'a massive theft.”
'The company failed to prevent sensitive information from falling into the hands of wrongdoers,” he said.
'The people affected by this are not numbers in a database. They are my friends, my family, members of my church, the members of my community, my neighbors,” Smith said. 'This breach has impacted all of them. It has impacted all of us.”
Smith also said Equifax was 'disappointed” with the rollout of a special website and call centers to deal with the fallout from the breach. The company 'struggled with the initial effort” to help consumers, he said.
Equifax has been criticized for waiting nearly six weeks to notify the public after learning of the hack July 29, and then initially making consumers give up their right to sue if they wanted free credit monitoring and identity theft protection. Equifax later backtracked on that requirement.
On Aug. 1, three Equifax executives sold thousands of shares of stock. All the shares sold for about $146 each. The company's stock sharply declined after the data breach was announced.
Equifax's board of directors has formed a special committee and is 'conducting a thorough review of the trading at issue,” Theodore M. Hester, a lawyer retained by Equifax, said in a letter Friday to Democrats on the House Energy and Commerce Committee.
'Equifax takes these matters seriously,” Hester wrote.
The stock sales were among several questions about the data breach that the lawmakers had asked Smith about in a Sept. 12 letter.
Smith said the data breach problems started March 8 when the Department of Homeland Security's Computer Emergency Readiness Team sent a notice to Equifax and other companies about the need to patch a vulnerability in software known as Apache Struts.
Equifax sent emails about the federal warning to workers responsible for the software, which is used in the company's consumer online disputes portal. But the 'vulnerable versions” of the software were not identified or patched, Smith said.
'Equifax's efforts undertaken in March 2017 did not identify any versions of Apache Struts that were subject to this vulnerability, and the vulnerability remained in an Equifax web application much longer than it should have,” Smith said. The company is investigating why.
Reuters 'This breach has impacted all of them. It has impacted all of us,' former Equifax CEO Robert Smith said in a prepared statement. Above, the company's headquarters in Atlanta.

Daily Newsletters