Back
Richard Smith
Former Chairman & Chief Executive Officer, Equifax

Equifax ex-CEO testifies about data breach on Capitol Hill

🎥 Oct 03, 2017 📺 ABC News ⏱ 180m
Richard Smith will face tough questions about the massive data breach when he appears before the House House Energy and ...
Watch on YouTube

About Richard Smith

Former Equifax CEO Richard Smith testified before Congress in 2017 and 2018 regarding a data breach that compromised personal information of over 145 million Americans. Smith stated that the criminal hack "happened on my watch" and said he took "full responsibility" for the incident. He apologized to affected consumers and attributed the breach to a combination of human error, including a failure to apply a software patch, and technological error involving a scanner that failed to detect the vulnerability. During questioning, Smith said that Equifax's general counsel and other executives who sold stock in early August 2017 did not know it was a breach at the time, describing the incident as "suspicious activity" with no indication that personally identifiable information had been compromised. Smith stated that upon his retirement he agreed to step down with no further compensation, no bonus, and no severance. In a separate hearing, Senator Elizabeth Warren questioned Smith about Equifax's profits, which Smith confirmed had increased by more than 80 percent since 2013 despite multiple data breaches. Smith also acknowledged that Equifax receives revenue from LifeLock, a credit monitoring service that saw increased enrollment after the breach.

Source: AI-verified profile updated from Richard Smith's recent appearances. Browse all interviews →

Transcript (494 segments)
G
Greg Walden0:09
Good morning. The Subcommittee on Digital Commerce and Consumer Protection will come to order. The chair now recognizes himself for five minutes for an opening statement. Good morning. Today we're here to get the facts, to learn what happened at Equifax that led to the personal information of over 143 million Americans' information being stolen. Americans deserve to know what Equifax is doing to fix the problem and help individuals that are impacted. Let's find out what happened. The public deserves to know what happened and what steps are being taken to protect their sensitive data going forward. Today's hearing needs to shed some much-needed information and light on this breach. We have received assurances from Equifax that Mr. Smith can speak for the company on concrete remediation steps that the company took in the aftermath to secure its computer systems and to protect the affected U.S. customers, as well as what happened when he was chief executive. As Chairman of the Digital Commerce and Consumer Protection Subcommittee, I often speak about the fact that we live in a digitally connected world. That fact of life can have many positive implications, far and wide-ranging for commerce, trade, communications, and entertainment. The breach is a massive reminder of the bad actors that are out there and the security challenges confronting our digitally integrated and data-powered economy. In this case, sensitive personal information that is used to build credit histories and allow individuals to engage in commerce, open credit cards, buy cell phones and appliances, and secure mortgages has been compromised. Reasonable security measures must be implemented, practiced, and continually improved by companies that collect and store data in order to guard against unauthorized access to sensitive personal information. Otherwise, consumers will face substantial financial harm. This risk is deeply concerning to me, and I know that the other members of the subcommittee share this view. Priority number one: we must protect Americans and work to safeguard their personal information online. The recent Equifax data breach is unprecedented, and it is also unique because of the sensitivity of the information stolen, including full nine-digit Social Security numbers. Over 143 million Americans are potentially impacted. This represents approximately 44 percent of the total U.S. population. In my home state of Ohio, approximately 5.2 million customers are likely affected. Based on the information released by Equifax, we are informed that massive amounts of personal and financial information was accessed from mid-May through July 2017, including names, birth dates, addresses, and in some cases driver's license information. In addition, over 200,000 people had their credit card information stolen, and over 180,000 people had credit dispute documentation stolen. This is a staggering amount of sensitive personal information. It impacts an extraordinary number of credit-viable Americans. That is in the hands of criminals that could result in fraud or identity theft. We need these numbers confirmed. Today we must understand the following: First, how did the hackers get into Equifax's system for so many weeks and pull so much information out of the system without being detected? Second, what processes and procedures were in place in the event of such a breach, and were those processes followed? There are many questions as to who knew what and when this information was known. This will have implications in other ongoing investigations. Further, the chief information officer and chief security officer made retirement announcements shortly after the public notice of the breach and have been unavailable for questions about their role. Again, despite months of delay, why was Equifax's notification and consumer protection processes still met with misinformation, glitches, and overall confusion? For example, there are numerous reports of difficulties accessing Equifax's dedicated website or call centers. And there were reports that the official Equifax Twitter account directed consumers to a fake website. I believe the American public deserves to know the facts about when and how Mr. Smith, company management, and the board of directors were made aware its systems were vulnerable to hackers, and how over 143 million sensitive personal data records were stolen. To that end, what were the steps taken and in what timeframe to notify and help individuals that were impacted? I look forward to getting these answers today and many more questions for the American people answered this morning. And at this time, I'll ask the gentlelady from Illinois, the ranking minority member, for five minutes for her opening statement.
J
Jan Schakowsky5:10
Thank you, Mr. Chairman, for holding this hearing. The Equifax data breach was massive in scale. 145.45 million American victims as of yesterday. I would call it shocking, but is it really? We have these under-regulated, private, for-profit credit reporting agencies collecting detailed personal and financial information about American consumers. It's a treasure trove for hackers. Consumers don't have a choice over what information Equifax, or for example TransUnion or Experian, have collected, stored, and sold. If you want to participate in today's modern economy, if you want to get a credit card, rent an apartment, or even get a job often, then a credit reporting agency may hold the key. Because consumers don't have a choice, we can't trust credit reporting agencies to self-regulate. Not like when you get sick at a restaurant and decide not to go there anymore. Equifax collects your data whether you want to have it collected or not. If it has incorrect information about you, it's really an arduous process — I've tried it — to get it corrected. When it comes to information security, you are at the mercy of whatever Equifax decides is right. And once your information is compromised, the damage is ongoing. Given the vast quantities of information and lack of accountability, a major breach at Equifax, I would say, would be predictable if not inevitable. I should really say breaches. This is the third major breach Equifax has had in the past two years. From media reports and the subcommittee's meeting with Equifax officials after the breach, it's clear to me that the company lacked appropriate policies and practices around data security. This particular breach occurred when hackers exploited a known vulnerability that was not yet patched. It was months later before Equifax first discovered the breach, and it was another several weeks before Equifax shared news with the consumers, this committee, the Federal Trade Commission, and the Consumer Financial Protection Bureau. Senior officials at the company are saying they weren't immediately aware that the breach occurred, and yet, by the way, there were executives who sold over a million dollars in stock just days after the breach was discovered but yet not reported. And for a lot of Americans, that just doesn't pass the smell test. The response to the breach was its own debacle. Equifax offered consumers credit monitoring services that initially came with a mandatory arbitration clause, which fortunately has been corrected. Equifax tweeted links to the wrong URL, directing victims to a fake website. The call center was understaffed. And Equifax has had to apologize for its post-breach response almost as much as it has apologized for the breach itself. Equifax deserves to be shamed in this hearing, but we should also ask what Congress has done or failed to do to stop data breaches from occurring, and what Equifax plans to do. The same day that Equifax breach went public, the House Financial Services Committee held a hearing on a Fair Credit Reporting Act liability-harmony act, a bill to protect credit reporting agencies like Equifax from class action suits. Imagine, in fact, Equifax was lobbying for this bill after the breach was discovered in July, still not reported. And for the 14 Republicans sponsoring this bill, should ask themselves whether this is really the industry they want to be in bed with. Like Equifax, need more accountability, not less. I agree with the CFPB Director Richard Cordray that the credit reporting agencies should be regulated to protect consumers' sensitive information. And then we need to go further. Last night, I reintroduced the Secure and Protect Americans' Data Act, along with Ranking Member Pallone and seven other members of the Energy and Commerce Committee. And our bill would establish one, strong data security standards; two, require prompt breach notification, which we didn't get; and three, provide appropriate relief for breach victims. Chairman Walden, American consumers don't just need answers, they need action. I hope that our bill can be a starting point for discussion on strengthening protections for Americans' data. Consumers deserve a whole lot better than they got from Equifax. And I yield back.
G
Greg Walden10:22
Thank you very much. The gentlelady yields back. The chair now recognizes the gentleman from Oregon, the chairman of the full committee, for five minutes.
I thank the chairman. We're here to do today what it appears Equifax failed to do over the last several months, and that's put consumers first. Our job is to get answers for the more than 145 million Americans who have had their personal information compromised and now fear they could be victims of fraud at any time. How could a major U.S. company like Equifax, which holds the most sensitive and personal data on Americans, so let them down? It's like the guards at Fort Knox forgot to lock the doors and failed to notice the thieves were emptying the vaults. The American people deserve to know what went wrong. We want a clear timeline of events and to understand what to expect moving forward. As chairman of the Energy and Commerce Committee, I've always tried to put our consumers first in everything we do on public policy. So today we'll begin to get the answers for the public, hold Equifax accountable, and make clear that businesses holding America's most sensitive data have a responsibility under existing laws to protect those data. Today gives whole new meaning to Mr. Smith Goes to Washington. It's not a run on the bank that's at issue, it's a run on financial records of 145 million Americans. And the consequences and the inconveniences for our fellow citizens is every bit as important to discuss today as the reasons behind why this breach occurred in the first place. Mr. Smith, as former chairman and CEO of Equifax, at the helm during and immediately after the breach, we appreciate your being here and we expect your candor and full cooperation as we march toward getting the facts in this case. While there's no such thing as perfect security, companies do have a legal obligation to protect sensitive consumer data. This diligence is necessary to both comply with existing laws and maybe more importantly, earn and keep the public's trust in a data-driven economy. Given the size of the breach and the sensitivity of the data, we expect to learn more about how Equifax failed to secure its systems and what contingency plans were in place. Further, we need to understand how information flowed through the organization and when you and other senior executives were notified about the breach. In other words, how important was cybersecurity to you as a CEO and to the rest of your executive team? Did your employees have a way to report to you if they had concerns about how the security team was functioning? While there are still many questions that need answers, a few details have emerged. First, the vulnerability that the hackers used to get into the Equifax system was discovered in early March. From the beginning, the vulnerability was described as critical and easily exploitable. That information was pushed out through multiple security information sharing channels, including by the U.S. Computer Emergency Readiness Team, to Equifax. For some period of time between March and August of 2017, the hackers were able to sit on Equifax's system and siphon out 145 million records without being detected. How did this go unnoticed? Further, is there a process in place to raise flags or alarms when massive amounts of data are pulled out of the Equifax system? Then there are questions about Equifax's response for consumers that we need answers to. Why was the consumer-facing website created on a separate domain from the main Equifax website? Did anyone raise concerns about creating more consumer confusion with a separate website? Are consumers able to sign up for the products offered by Equifax today? How many consumers have placed a fraud alert on their account or frozen their credit? And on top of all the other issues, multiple times Equifax tweeted the wrong URL, directing consumers to the wrong website to check if they were part of a breach. Talk about ham-handed responses. This is simply unacceptable, and it makes me wonder whether there was a breach response plan in place at all, and if anyone, who is in charge of overseeing and executing that plan. I have to agree with the interim CEO when he said there's insufficient support for consumers. It's important that as Congress does its work on public policy issues, that the Federal Trade Commission and other agencies, including law enforcement agencies, continue their work, especially in light of recent reports that indicated there are markers of nation-state activity involved with this hack. But today, Mr. Smith, I and the rest of the committee, and Congress and the country, expect the answers. After all, the buck does stop with you as CEO. And I thank you for being here, and I return the balance of my time.
Thank you very much. The gentleman yields back. And the chair now recognizes the gentleman from New Jersey, the ranking member of the full committee.
F
Frank Pallone15:20
Thank you, Mr. Chairman. Well, I understand that law enforcement and internal investigations into this incident are still ongoing. I expect to get more information today on what happened and why it took so long to inform the public. Most importantly, we want answers for consumers, because Equifax's response to this breach has been unacceptable. So too has been Equifax's ongoing lackadaisical attitude when it comes to protecting consumer data. It's been four weeks since the breach was made public and at least 10 weeks since it was discovered by Equifax's employees, yet Equifax's customer service has been confusing and unhelpful. Equifax even tweeted a link to a fake website. Many of the remedies Equifax is now offering to consumers were not upfront or in good faith. They were forced out of the company only after a public outcry, and they are still inadequate. It's hard to imagine that anyone at Equifax thought it was a good idea to offer only one year of credit monitoring with an arbitration clause at first, to boot. Free and comprehensive credit monitoring and identity theft protection should be offered for far longer than a year. Most recently, Equifax added lifetime credit locks to its offering, which consumer advocates suggest are weaker than credit freezes. Regardless, a lock or a freeze at only one credit bureau is almost useless. Equifax should work with the other credit bureaus to immediately create a free, quick, and easy-to-use freeze and unfreeze one-stop shop. And because credit freezes or locks may not work for everyone going forward, Equifax should do more than credit locks. It should give consumers more control over how their data is used and stored. In addition, if Equifax wants to stay in business, its entire corporate culture needs to change to one that values security and transparency. After all, this is not Equifax's first data breach in the past year. Consumers do not have any say in whether or not Equifax collects and shares their data, and that's what makes this breach so concerning. This is unlike other breaches at stores such as Target and Michaels, where consumers could make a choice and change their shopping habits if they were upset with how the company protected data. That's simply not the case with Equifax. While data breaches have unfortunately become commonplace, it's long past time for Congress, beginning with this committee, to act. Since at least 2005, this subcommittee has been considering data breach legislation, but it's never become law. And it's time we change that. Yesterday, Ranking Member Schakowsky and I reintroduced the Secure and Protect America's Data Act. This bill would require enforceable, robust data security practices and meaningful notice to consumers. It would also give additional protections to consumers after a breach. Of course, breaches will continue to occur, but they occur more often when there is no accountability and no preventative measures are in place. And our bill will not stop mistakes and cyber crimes from happening, but we need to start somewhere. So, Mr. Smith, I read your op-ed in USA Today last month and the new CEO's op-ed in the Wall Street Journal last week, and I appreciate that you're both sorry, but my question is: what now? I'd like to now yield the remainder of my time to my colleague from New Mexico.
B
Ben Ray Luján18:37
Thank you to our ranking member, Mr. Pallone, and I thank the committee's leadership for organizing this important hearing. 145,500,000 Americans. 145.5 million people at risk because of Equifax's failure. Now, Mr. Smith, the American people deserve answers, and I hope you are prepared to provide them, not just about what caused the breach, but what Equifax is doing to prevent this from happening again, and to ensure that those who were harmed are made whole. I worry that your job today is about damage control, to put a happy face on your firm's disgraceful actions and then depart with a golden parachute. Unfortunately, if fraudsters destroy my constituents' savings and financial futures, there's no golden parachute awaiting them. We have questions, and it's our expectation that you have concrete answers. And I hope this hearing is just the start of our committee's work. We need to work together to hammer out real solutions. I recently took a step in that direction by introducing the Free Credit Freeze Act to allow consumers to protect themselves by freezing and unfreezing their credit at no charge. It is unconscionable that Equifax failed so spectacularly to protect people's most sensitive personal data. It's even more reprehensible that the same company profits from the pain that they have caused. And I certainly hope that we can get some assurances from the committee's leadership that we will have a markup and a hearing on legislation to address this mess. And I hope that that assurance can be given before the holidays of 2017. I yield back the balance of my time.
G
Greg Walden20:33
Thank you very much. The gentleman yields back. And this concludes the member opening statements. The chair would remind members that pursuant to the committee rules, all members' opening statements will be made part of the record. Today we have Mr. Richard Smith, the former chairman and CEO of Equifax Inc., who is here to testify before the subcommittee. Mr. Smith will have the opportunity to give an opening statement followed by a round of questions from our members. And Mr. Smith, you are recognized for five minutes.
R
Richard Smith21:06
Thank you. Thank you, Chairman Walden, Ranking Member Pallone, Chair Latta, Ranking Member Schakowsky, and the honorable members of the subcommittee. It's an honor to be here before you today. My name is Rick Smith, and for the last 12 years I have had the honor of being the CEO and the chairman of Equifax. Earlier this week I submitted a written testimony which at this time I don't plan on going into any detail on that, but rather I'm here today to explain to you and the American people how criminal hackers were able to steal personal information on over 145 million Americans from our servers, and as importantly, to discuss with you today what the company's response was to the criminal hack. The criminal hack happened on my watch as CEO. I am ultimately responsible, and I take full responsibility. I'm here today to say to each and every person affected by this breach, I truly and deeply am sorry for what happened. I've talked to many consumers. I've read your letters. And Equifax is committed to make it whole for you. Americans have a right to know how this happened. I am prepared to testify today about what I've learned and what I did about this incident in my role as CEO and as chairman of the board, and also what I know about the incident as a result of being briefed by the company's investigation, which is ongoing. We know now that this criminal attack was made possible because of a combination of human error and technological error. Human error involved a failure to apply a software patch to a dispute portal in March of 2017. Technological error involved a scanner which failed to detect that vulnerability on that particular portal. Both errors have since been addressed. On July 29th and July 30th, suspicious activity was detected, and the team followed our security incident protocol. The team immediately shut down the portal and began our internal security investigation. On August 2nd, we hired top cybersecurity forensic and legal experts, and at that time we notified the FBI. To be clear, we did not know the nature or the scope of the incident. It was not until late August that we concluded that we had experienced a major breach. Over the weeks leading up to September 7th, our team continued working around the clock to prepare. We took four steps to protect consumers. Step number one: determining when and how to notify the public, relying on the advice of our experts that we needed to have a plan in place as soon as we announced. Step two: helping consumers by developing a website, staffing up massive call centers, and offering services free to every American. Three: preparing for increased cyber attacks which were advised by the cybersecurity experts that we should expect. And finally: continuing to coordinate with the FBI and their criminal investigation of the hackers and also to notify other federal and state agencies. In the rollout of our remediation program, mistakes were made, which again I deeply apologize. I regret the frustration that many Americans felt when our websites and call centers were overwhelmed in the early days. It's no excuse, but it certainly did not help that Hurricane Irma took down two of our larger call centers in the first few days after the breach. Since then, however, the company has dramatically increased its capacity, and I can report to you today that we have handled over 420 million consumer visits to our website in just over three weeks, and the wait times at the call centers have been substantially reduced. At my direction, the company offered a broad package of services to all Americans. In addition, we developed a new service, available on January 31st, 2018, that will give all consumers the power to control access to their credit data by allowing them to lock and unlock their credit files when they want. They can do that for free for life. Putting the power to control access to credit data in the hands of the American consumer is a step forward. I look forward to discussing this new tool with you during my testimony. As we've all painfully learned, data security is a national security problem. Putting consumers in control of their credit data is a first step towards a long-term solution to the problem of identity theft. No single company can solve a larger problem on its own. I believe we need a public-private partnership to evaluate how to best protect Americans' personal data going forward. I look forward to being a part of that dialogue. Chairman Walden, Ranking Member Pallone, Chair Latta, Ranking Member Schakowsky, and the honorable members of the subcommittee, thank you again for inviting me here today to speak to you. I will close by saying again how sorry I am for this breach. On a personal note, I want to thank the many hardworking and dedicated employees who worked with me so tirelessly over the past 12 years at Equifax. Equifax is a very good company with thousands of great people waking up every day trying to do what is right. I know they'll continue to work tirelessly as we have over the past two months to right the wrong. I'm looking forward to answering your questions. Thank you.
G
Greg Walden27:47
Thank you very much. This concludes our witness testimony. We'll move into the question and answer portion of our hearing. I'll begin with the questions. I recognize myself for five minutes. And I would remind members, because we do have quite a few members that want to ask questions today, I'm going to try to keep the five-minute rule on questions in place, so you'll hear the tapping. But I will begin with the questioning. Mr. Smith, the timeline of events is raising red flags. I would like to ask you about it. According to your statement, the first time you heard about the breach of security was on July the 31st of 2017. Is that correct?
R
Richard Smith28:27
Yes, Congressman, that is correct.
G
Greg Walden28:30
And you first asked for a briefing about the breach on August the 15th. Is that correct?
R
Richard Smith28:37
Uh, yes, that is correct.
G
Greg Walden28:39
And the first time the board of directors was notified about the breach was August the 24th. Is that correct?
R
Richard Smith28:44
The full board, Congressman. On the 22nd of August, I notified our lead director, presiding director at that time. The full board was briefed on the 24th, again on the 25th, and subsequent meetings after that.
G
Greg Walden28:56
All right. And you notified the public about the breach on September the 7th. Correct?
R
Richard Smith29:01
That is correct.
G
Greg Walden29:03
Okay. You state in your testimony that you began developing the remediation for consumers on August the 24th or the 25th. Why was there a 10-day delay between you finding out that personal information had likely been stolen and beginning to develop the remediation plan? And do you think that 10-day window was responsible for having learned about that personal information being stolen to start talking about how to talk to the consumers?
R
Richard Smith29:26
Congressman, I understand the question. If I may go back to the timeframe of the 31st, so if you go the 29th and 30th, someone in security had detected what they deemed a suspicious activity. That is something that happens routinely around our business. On the 30th, they bring down this particular portal, and they start their own internal investigation. As I had mentioned in my opening comments and my written testimony, on the 2nd of August, they had engaged leading forensic experts, cyber experts, and King & Spalding, a leading law firm and their cybersecurity team. When you talk to the forensics experts, they will tell you the complications of trying to understand where these criminals were, the footprints they had left, the inquiries they had made. It is a cumbersome, cumbersome process. That's why it took weeks before we had indication for the breadth and the depth of the issue, which brought us to the August 24th date that you had mentioned.
G
Greg Walden30:41
Let me back up to July the 31st, when you learned. You're talking with the experts at that time. You learned about the breach, and you testified that you did not know that personal information had been stolen at that point. But did you ask anyone if personal information had been stolen when you found out about that breach?
R
Richard Smith30:59
Congressman, on the 31st, all I was told at that time was that security had noticed a suspicious movement of data out of an environment we call a dispute portal. It was not until later that they understood that was an actual dispute document. We had no indication on the 31st of July that there was any PII information that was vulnerable.
G
Greg Walden31:26
Okay, so again, not knowing if that personal information was being stolen at that time, your company's built on data. At any point, did you think that was important, or did somebody in the company start looking at whether personal data had been stolen at that point?
R
Richard Smith31:43
Congressman, I can tell you we were working with the best forensic auditors in the business. They do this for a living. We had a great cyber team from King & Spalding with us. It took them time. At that time, they did not know if data had been compromised, exfiltrated, or what the data was.
G
Greg Walden32:03
If we could go back. When you did find out about the breach in that conversation with your chief information officer, Mr. Webb, how did he exactly tell you that there had been a breach? Was it a phone call, an email, in person? How did he notify you of the breach?
R
Richard Smith32:18
It was a face-to-face brief meeting on the 31st. At that time, he had just learned as well, so the day was very, very fresh to him. And the incident was described as an incident, not as a breach.
G
Greg Walden32:35
Is that the normal way for that information if there had been a breach at the company to notify someone? For the CIO to come and just give a face-to-face? Is that the standard operating procedure?
R
Richard Smith32:47
Congressman, at that time we had no indication it was a breach. It was a suspicious activity.
G
Greg Walden32:55
Did you tell anyone else in senior management or any other members of the board of directors about the breach at that time, or just not until you told the one call on August the 22nd and then the 24th before the rest of the board of directors? Did anyone else know about the breach?
R
Richard Smith33:10
Again, it's important to say on July 31st it was not — we did not know it was a breach at that time, suspicious activity only. The first notification to the board was the lead director on the 2nd of August, which followed in the chronology of events a meeting I had with our cybersecurity experts and our outside counsel that occurred on the 17th of August. That's when the picture was starting to develop.
G
Greg Walden33:41
Thank you. My time's expired. And I'll recognize the gentlelady from Illinois, the ranking member, for five minutes.
J
Jan Schakowsky33:51
Thank you, Mr. Chairman. I'm going to get right to it. I wanted to ask some questions about John Kelly, the chief legal officer, who I understand is responsible for security at Equifax, or was at least at the time of the breach and its discovery. Is that right?
R
Richard Smith34:09
That is correct, Congresswoman. And Mr. Kelly in turn reports directly to you, the CEO. Correct?
J
Jan Schakowsky34:14
Correct. Okay. So we were told that Mr. Kelly was informed by the chief security officer the week of July 30th — we've just been talking about that — that a cybersecurity incident had occurred. Is that correct?
R
Richard Smith34:29
He was notified, as my understanding, on the 31st of July. It was a suspicious activity in a particular environment called a web portal that was a dispute environment.
J
Jan Schakowsky34:41
We were told that Mr. Kelly — this is our staff — was informed at the same time that the incident might have compromised personally identifiable information. Is that correct?
R
Richard Smith34:55
The only knowledge I have is he was notified on the 31st that there was suspicious activity in a consumer dispute portal.
J
Jan Schakowsky35:01
Well, we were told that Mr. Kelly then wrote a short memo to you regarding the incident. Is that correct?
R
Richard Smith35:09
Correct, Congresswoman. In his email, it said some suspicious activity.
J
Jan Schakowsky35:18
Okay. Around that same time, three Equifax executives sold over one million dollars of Equifax stock, on August 1st and August 2nd. And it's reported that Mr. Kelly was ultimately responsible for approving those sales. Is it true that Mr. Kelly or one of his direct reports would have been required to sign off on these stock sales?
R
Richard Smith35:49
Yes, Mr. Kelly, who is our general counsel, owns the clearance process.
J
Jan Schakowsky35:55
And he had to sign off? Yes.
R
Richard Smith35:57
Yes, he had to. He was supposed to sign off. Yes.
J
Jan Schakowsky36:01
Did any of these three executives have knowledge that a cybersecurity incident had occurred?
R
Richard Smith36:09
To the best of my knowledge, Congresswoman, no.
J
Jan Schakowsky36:13
When were they informed that the incident had occurred?
R
Richard Smith36:20
I don't know exactly the date that they were informed, but to the best of my knowledge, they had no knowledge at the time they cleared their trades through the general counsel.
J
Jan Schakowsky36:26
Do you know for sure that they didn't?
R
Richard Smith36:29
To the best of my knowledge, they did not know.
J
Jan Schakowsky36:33
And Mr. Kelly, who we were told knew of the breach and that it contained personal information, and yet still approved the stock sale. Is he still chief legal officer for Equifax?
R
Richard Smith36:43
Congresswoman, I would come back to it again: he did not know it was a breach when he approved it. It could have been a breach. All he knew at the time, my understanding, was suspicious activity when he approved the sales.
J
Jan Schakowsky36:56
What the heck does suspicious? It could be a breach, right?
R
Richard Smith37:02
It was deemed suspicious activity. We had no indication that PII was in fact compromised at that time. We had no idea if data was exfiltrated at that time.
J
Jan Schakowsky37:14
So now I understand that you agreed to forgo your 2017 bonus, which has been about three million dollars for the past two years. Correct?
R
Richard Smith37:25
That is correct.
J
Jan Schakowsky37:26
But it's been reported that you will still retain 18 million dollars in pension benefits from Equifax. Is that accurate?
R
Richard Smith37:31
That is correct. Retiring, which is the category right now, although the company maintains the right to change that designation also.
J
Jan Schakowsky37:41
Retiring also means you'll be free to sell your Equifax stock, which is worth about 24 million dollars. Is that correct?
R
Richard Smith37:50
Congresswoman, that calculation is hard to say. It's a complicated calculation. It depends on the total shareholder return of the company at the time the stock vests. There are multiple variables. That may be an estimate. I've seen different estimates, but it's hard to say what that number is. They won't know until the end of the year.
J
Jan Schakowsky38:04
And that's in addition to Equifax stock you sold earlier this year for 19 million dollars. Is that correct?
R
Richard Smith38:13
Uh, that sounds correct.
J
Jan Schakowsky38:15
And according to one report, you could be eligible for 22 million dollars in performance-based compensation, depending on how Equifax stock performs in the next three years. Is that right?
R
Richard Smith38:27
Let me be very clear, if I may, Congresswoman. When I announced my retirement and thought it was best for the company to move forward with a new leader, I agreed to step down at that time with no further compensation. I agreed I should not get a bonus. I agreed there would be no severance. I asked for nothing beyond what I'd already earned.
J
Jan Schakowsky38:48
I was just informed by staff that the chief security officer told the chief legal officer verbally that there was PII. That, according to a call with staff yesterday, that actually there was a mention of the breach of personally identifiable information. The CSO told — yeah, I told — I sent a call yesterday is what I just heard from staff. August 1? I have no documentation, no insight, no knowledge that anyone in the company had informed me or, in that case, the chief security officer or the chief general counsel, that there was a breach on July 31st. Is that what you said?
R
Richard Smith39:35
Yes. Oh, we didn't say a date. I'm told that our staff didn't say a date.
J
Jan Schakowsky39:40
Okay. Let me just say I'm glad the FBI is looking into it. Many state attorneys general, the city of Chicago has sued, so we'll probably get more information that way as well. Thank you.
G
Greg Walden39:53
Thank you very much. The gentlelady's time has expired. The chair now recognizes the chairman of the full committee, the gentleman from Oregon, for five minutes.
Thank you, Mr. Chairman. Mr. Smith, thanks again for being here today. As you know, this is a sample of a copy of an Equifax credit report in my hand. It lists Social Security numbers, address, credit history, debts — all the sort of personal financial information. It's the lifeblood of Equifax, right? I mean, these data points are really, really important to what you do as a company.
R
Richard Smith40:25
Congressman, that's correct.
G
Greg Walden40:28
It's a three-billion-dollar company, data on 820 million customers worldwide. And yet it appears this breach happened because the company didn't know it was running certain software on its system, right? The Apache Struts software that had the patch requirement.
R
Richard Smith40:47
Yeah, Congressman, as I alluded to in my opening comments and in my written testimony, there was a human error and a technology error that did not allow us to identify — and I think that's what we're trying to get to here.
G
Greg Walden41:00
If I understand it right, your own information technology system did not tell the Equifax security division that the Apache Struts software, which contained the vulnerability that led to this breach, was running on the Equifax system. How did that happen?
R
Richard Smith41:15
Congressman, the day after the notification came out from CERTs, the security team notified a wide range of people in the technology team who were responsible for them finding the patch, finding the vulnerability, applying the patch. And then days later, as is typical protocol, to deploy a technology scanner to then go look for the vulnerability, find the vulnerability. If it found a vulnerability, it knew it was not patched. Both the human deployment of the patch and the scanning deployment did not work. The protocol was followed.
G
Greg Walden41:55
Okay, so then people ask us, how does that happen? If a sophisticated company as you headed is, with so much at risk, how does this happen? And we have colleagues that say we're going to double the fines, triple the fines, put fines in, do all these things. But how does this happen when so much is at stake? I don't think we can pass a law that — excuse me for saying this — but fixes stupid. I can't fix stupid, as a colleague of mine used to say. With so much at risk, I've talked to other software companies and people in this space who say some companies have an automated system that when a patch comes out, it automatically gets installed. That's not what you had necessarily, right?
R
Richard Smith42:47
I'm unaware of an automatic patch system we have in place. Security gets notifications, and it's not uncommon to get notifications from software providers routinely about vulnerabilities that are discovered. They followed the protocol, which is they notified the appropriate people within the timeframe that the protocol called for. Unfortunately, the human error was that they did not find the patch.
G
Greg Walden43:12
If I could, the human error piece you reference — is that that they didn't know that that particular software was running on your system? Apache Struts was running, that's what needed patching, right?
R
Richard Smith43:24
Congressman, great question. If I may clarify, please. The human error was that the individual who was responsible for communicating in the organization to apply the patch did not.
G
Greg Walden43:39
So does that mean that that individual knew that the software was there and it needed to be patched and did not communicate that to the team that does the patching? Is that the heart of the issue here?
R
Richard Smith43:50
That is my understanding, sir.
G
Greg Walden43:54
And there's no — I was on a bank board for a while, and you know we always had sort of double checks on everybody, right? Do you not have a double check of some sort, an audit of some sort? It seems like that was a single point. The double check was the scanning device that was deployed a few days later. But the scanning device — I don't know how that process works — does it know you have that software? Do you have to tell it what you're scanning for?
R
Richard Smith44:20
It's the latter. You've got to tell it what it's looking for. It scans the environment. And so the individual who didn't tell the — I'll call it the IT team, the security team — that's where the individual failed.
G
Greg Walden44:33
Was it the same person telling them what to look for?
R
Richard Smith44:37
No. The scanner is deployed by the security team. And I should clarify there that the rationale, the reason why the scanner, the technology piece, did not locate the right vulnerability is still under investigation by outside counsel.
G
Greg Walden44:50
All right. One final question. You've referenced this suspicious movement of data. You've referenced incident. The American people think all of that is breach. How regularly did you have incidents or suspicious movement of data? Is this something that happens frequently?
Routine thing that people call: 'Hey, we had another incident, we had another suspicious movement of data.' Or was this sort of outside normal?
R
Richard Smith45:15
Congressman, thank you for the operations. As you alluded to in your comments, we do have a lot of data and our primary goal is to protect that data. We have experienced millions of suspicious activity against our database on any given year. But to the point that the head of your security team comes to you and says, 'Hey, we've got another one' – oh yeah, that is not uncommon. How often would that happen in the course of a week that they would come to the CEO and say heads up? I don't have a number for you, Congressman, but it's not uncommon. It's not uncommon for us to engage forensic audit firms, it's not uncommon for us to engage outside counsel to help us think things through when there's suspicious activity. It's a part of doing business in a data business, as you alluded to.
G
Greg Walden46:06
Thank you for the indulgence on the committee. I yield the balance of my time.
The gentleman yields back and the chair recognizes the ranking member of the full committee, the gentleman from New Jersey, for five minutes.
F
Frank Pallone46:19
Thank you, Mr. Smith. You testified that on August 11th you were informed that hackers had stolen, quote, 'a large amount of consumers' personally identifiable information,' unquote, in this incident. And on August 17th, I guess a week later, you said in a speech, and I quote, 'Fraud is a huge opportunity for Equifax. It's a massive growing business for us,' unquote. So I'm just looking for a number, Mr. Smith. At the time you gave that speech, roughly how many consumers did you believe had been compromised by the breach?
R
Richard Smith46:52
If you could, Congressman, if I may clarify. I think you alluded to August 11th date. August 11th initially, and then August 17th in the second speech. August 11th I had no indication, I was not informed at that time. My notification was before the August 17th meeting, and you alluded to a speech.
F
Frank Pallone47:09
Well, I'm just – yeah, I mean on the 17th you said in a speech, 'Fraud is a huge opportunity for Equifax, it's a massive growing business for us.' I'm just looking for a number. At the time, roughly how many consumers did you believe had been compromised by the breach on August 17th, which is I think on and around the date you had talked about?
R
Richard Smith47:24
I gave a speech. We did not know how much data was compromised, what data was compromised. That story was still developing. And that speech that you're alluding to is a very common speech we have in communities. I think this happened to be at a university that we talked to them. But at that time when I gave that speech, I did not know the size, the scope of the breach.
F
Frank Pallone47:51
All right. During your tenure at Equifax, you expanded the company's business into packaging and selling other people's data. And in that August 17th speech, you explained that having free data with a gross margin of profit of about 90 percent is, and I quote, 'a pretty unique model.' And I get that this unique model is a good deal for Equifax, but can you explain how it's a good deal for consumers?
R
Richard Smith48:16
Thank you, Congressman. I think I understand the question. Our industry has been around for a number of years, as you know. In fact, Equifax is a 118-year-old company. We're part of a federally regulated ecosystem that enables consumers to get access to credit when they want access to credit, and hopefully the best rates available to them at that time. So we're very vital to the flow of economy, not just in the US but around the world.
F
Frank Pallone48:42
All right. And I want to turn to what Equifax is offering consumers in the wake of this breach, specifically the free credit lock service that is supposed to be introduced next year. We've been told that this free credit lock service could require consumers to consent to Equifax sharing or selling the information it collects from the service to third parties with whom the individual already has a business relationship, for marketing or other purposes. Is that true?
R
Richard Smith49:08
This product will be a web-enabled, mobile-enabled application that will allow a consumer, at the time he or she – if they decide they want access to credit – you can simply toggle on, toggle off that application to give the bank, credit card issuer, the auto lender access to the credit file to approve their loan.
F
Frank Pallone49:30
Well, by agreeing to use Equifax's lock service, will consumers also be opting into any additional marketing arrangements, either via Equifax or any of its partners?
R
Richard Smith49:43
Congressman, we're trying to change the paradigm. What I mean by that is this will be an environment viewed as a service, a utility, not a product. There'll be no cross-selling, upselling, or any products available to the consumer when they go to get and sign up for the lock product. It's a service to them, and that's the only product, the service they'll be able to get.
F
Frank Pallone50:03
Yeah, well, will Equifax give consumers an easy and free method to choose not to share their data in this way, even if the consumer already has a business relationship with the third party?
R
Richard Smith50:14
Yeah, Congressman. I envision as this evolves over time, the consumer will have the ability to invite into their world who they want to have access and who they do not. It'll be their choice, their power, not ours, to make that decision.
F
Frank Pallone50:28
Now last week, the interim CEO announced that by January 31st of 2018, Equifax would make locking and unlocking of a person's Equifax credit report free forever. A credit report lock is already included in TrustedID Premier and other services like credit monitoring and identity theft insurance. Will that still end after one year?
R
Richard Smith50:52
Congressman, a couple of differences. Number one, the product we offer today for consumers protects the consumer at the same level of protection they'd get January 31st. The difference is today is a browser-enabled product or service. The 31st of January, it'll be an application, much simpler and easier for the consumer to use. The protection is largely the same. So they get this free service when they sign up through for one year. At the end of one year, effective January 31st of 2018, it goes into the new lock product.
F
Frank Pallone51:29
I guess, you know, the difference other than not expiring between the credit report lock that is part of TrustedID Premier and the credit locking tool that will be available in January – why not just extend the freeze program?
R
Richard Smith51:43
There's a difference between the freeze product, which came to pass with FACTA back in 2003, passing the law in 2004, that is now governed by state laws in all states. And it's a cumbersome process for a consumer in many cases. Some states require you to mail in your request for a freeze, and then we must mail you a PIN. So your ability to get access to credit when you want credit is encumbered. A consumer could go to a car dealer or to a bank to get a credit card, forget his or her PIN on a freeze product, have to go back home, look for the PIN, mail the PIN in. So it's a cumbersome process. The lock product we're offering today is a big step forward. The lock product for the 31st of January is an even further step forward.
F
Frank Pallone52:32
My time is run out, Mr. Chairman.
G
Greg Walden52:35
Well, thank you very much. The gentleman's time has expired. The chair now recognizes the chairman emeritus of the full committee, the gentleman from Texas, for five minutes.
C
Congressman from Texas52:44
Thank you, Mr. Chairman. And since I'm not a member of this subcommittee, thank you for your courtesy and allowing me to ask questions. Mr. Smith, what's the market value of Equifax? What's your company worth? Or your phone? Yeah, Congressman, last time I checked it's somewhere close to $13 billion. $13 billion. I'm told by my staff that this current data breach was about 143 million people. Is that right? We were informed yesterday from the company that is typical in a forensic audit, there was some slight movement and the number is adjusted. Press release came out from the company last night, it's 145.5. Well, okay, I appreciate your accuracy there. But under current law, you're basically required to alert each of those that their account has been hacked, but there's really no penalty unless there is some sort of a lawsuit filed and the Federal Trade Commission or a state attorney general files a class action lawsuit against your company. So you're really only required to notify everybody and say, 'So sorry, so sad.' I understand that your company has to stay in business, has to make money, but it would seem to me that you might pay a little bit more attention to security if you had to pay everybody whose account got hacked a couple of thousand bucks or something. What would the industry reaction be to that if we passed a law that did that?
R
Richard Smith54:36
Congressman, I understand your question. I think the path that we were on when I was there and the companies continued is the right path. And that's the path of allowing the consumers to control the power of who and when access is the credit file going forward.
C
Congressman from Texas54:55
The consumer can't control the security of your system. That is true, sir. Your security people knew there was a problem, and according to staff briefings that I've been a part of, they didn't act in a very expeditious fashion until the system had already been hacked. And I mean, you're to be commended for being here. I don't think we subpoenaed you, I think you appeared voluntarily, which shows a commendable amount of integrity on your part. But I'm tired of almost every month there's another security breach, and it's okay, we have to alert you. I check my file to see if I was one of the ones that got breached, and apparently I wasn't. I don't know how I escaped, but I didn't get breached. But my staff person did. And we looked at her reports last night, and the amount of information that's collected is way beyond what you need to determine if she's creditworthy for a consumer loan. Her basically entire adult history going back 10 years, everywhere she's lived, her name, her date of birth, social security number, phone numbers, addresses, credit card, student loans, security clearance applications for federal employment, car insurance, even employment history of jobs that she worked when she was in high school. That's not needed to determine whether she's worthy of getting a $5,000 credit card and loan or something. And now it's all out in the netherworld of whoever hacked it. I can't speak for anybody but myself, but I think it's time at the federal level to put some teeth into this, and some sort of a per account payment. And again, I don't want to drive credit bureaus out of business and all of that, but we could have this hearing every year from now on if we don't do something to change the current system. So I would hope that you'd go back to your peers and work with the committee, the chairman and the subcommittee chairman and ranking member, and let's figure out something to do that actually gives an incentive to the industry to protect ourselves. And the only way I know to do it is to find a per account hacked that's large enough that even a company that's worth $13 billion would rather protect their data and probably not collect as much data than just come up here and have to appear and say we're sorry. With that, Mr. Chairman, thank you for your courtesy, and I yield back.
G
Greg Walden57:56
The gentleman yields back. The chair now recognizes the gentleman from New Mexico for five minutes.
B
Ben Ray Luján58:02
Thank you, Mr. Chairman. Mr. Smith, there is a difference between a locked product and a freeze, correct? Those are two different things.
R
Richard Smith58:10
Congressman, the process is a little different, but as far as the consumer and the protection that he or she would get from doing one versus the other, it is virtually, if not exactly, the same.
B
Ben Ray Luján58:28
It's like, well, 'virtually almost exactly' is not the same. It's the same? Are they different?
R
Richard Smith58:30
It's the same.
B
Ben Ray Luján58:32
So your lock product is the same as a freeze as far as the protection?
R
Richard Smith58:35
We'll get into that later. I appreciate that clarification. Will Equifax be willing to pay for this freeze at Experian and TransUnion for consumers whose information was stolen?
B
Ben Ray Luján58:42
You're referring to the freeze or the lock? You said they're the same, so yeah. Right now we offer a free lock product as you know for one year, and then a free lifetime lock product for life starting January 31st, 2018. And that also extends to Experian and TransUnion?
R
Richard Smith58:58
No, sir, it does not.
B
Ben Ray Luján59:09
Would Equifax – let me repeat the question. Will Equifax be willing to pay for that freeze, for that lock, at Experian and TransUnion for consumers whose information was stolen through Equifax?
R
Richard Smith59:17
Congresswoman, the companies have come out with what they feel is a comprehensive set of different services today in a lifetime lock. I would encourage – to be clear, I would encourage TransUnion and Experian to do the same. It's time we change the paradigm, give the power back to the consumer to control who accesses his or her credit data. It's the right thing.
B
Ben Ray Luján59:44
I'm down to limit the time, I apologize. I'll take that as a no, that Equifax will not pay for Experian and TransUnion consumers. Do you think consumers should have to pay a penalty for your mistake, including potential identity theft, false credit accounts, fraudulent tax returns, or medical identity theft? Or do you commit to compensating any consumers who suffer harm as a consequence of your breach?
R
Richard Smith1:00:04
We take this seriously. I've apologized, I apologize again to the American consumer. We've offered a comprehensive set of products for free.
B
Ben Ray Luján1:00:13
Mr. Smith, will those comprehensive sets of products make consumers whole?
R
Richard Smith1:00:17
It will protect them going forward.
B
Ben Ray Luján1:00:19
Will they make them whole? Yes or no?
R
Richard Smith1:00:23
It's hard for me to tell if someone's been harmed, so I can't answer the question.
B
Ben Ray Luján1:00:28
If someone's credit has been stolen and someone went and opened up a bunch of their accounts, bought furniture, bought cell phones, bought a bunch of fuel, and now this consumer can't fix their history, they've been harmed. In that case, will Equifax make that person whole?
R
Richard Smith1:00:40
Congressman, as I said, I apologize. We've offered them a comprehensive...
B
Ben Ray Luján1:00:47
Thank you very much, sir. So I want to go back to the line of questioning earlier from Mr. Pallone. On August 11th, in your prepared testimony, it says that you are aware of a large amount of consumer PII. On August 15th, it says in your prepared testimony PII had been stolen, it appeared likely, and that you requested a detailed briefing to determine how the company should proceed. On August 17th, it says you held a senior leadership meeting to receive the detailed briefing on the investigation. You gave a speech also on the 17th about profiting off of fraud with these new markets. You shared with Mr. Pallone that you were not aware of PII being stolen. What is it?
R
Richard Smith1:01:25
Congressman, on the 17th I had the full debrief from Mandiant, our forensic auditors, outside counsel, and my team. I was aware on the 15th that there had been some PII compromise, but not how much or the scope.
B
Ben Ray Luján1:01:41
I appreciate that clarification. You were aware it was stolen, you just were not aware how much.
R
Richard Smith1:01:45
I was not aware it was stolen. I was aware there was...
B
Ben Ray Luján1:01:47
You just – it says in your prepared testimony that you were aware that you asked for a detailed briefing to determine how the company should proceed. So you were aware that PII was stolen on the 15th. Is that true or not true?
R
Richard Smith1:01:58
At that time, the 17th was the detailed review of when I learned about PII. And even at that time, which PII was it stolen, was it not stolen – those details came to life, Congressman, over the course of August.
B
Ben Ray Luján1:02:15
Mr. Smith, on August 15th, were you aware that there was PII that was stolen or not?
R
Richard Smith1:02:24
On August 15th, regardless of the amount, were you aware of that?
B
Ben Ray Luján1:02:26
On August 15th, I was made aware that hackers, criminal hackers, had gotten into our system and had some PII information.
R
Richard Smith1:02:35
Well, we can revert to your prepared testimony. The other question that I have that Ms. Schakowsky was asking on is: Chief Legal Officer John Kelly – still employed by you or by Equifax?
B
Ben Ray Luján1:02:48
Yes, he is.
R
Richard Smith1:02:51
And you were the CEO at the time that approved the terms of the retirement for David Webb and Susan Mauldin. Is there a classification as 'retired permanent' or could it potentially change to 'fired for cause' like a cure?
B
Ben Ray Luján1:03:02
There's an investigation going on by the board at this time. And Mr. Chairman, I know that my time has collapsed, shared if you will. But there's an article in WGN-TV that talks about Equifax doing their own investigation into the three executives that sold their stock and profited. And I guess they must have a pretty good investigative team there, because between the press release that happened on Friday or whatever it came out, and then a story on Sunday, and today we have a revelation that those folks didn't know that this breach took place. I just hope we get to the bottom of this. And again, Mr. Chairman, I hope that we can be given assurance to the committee and to the American people that this committee will have a markup and a hearing with bills that we can take to the floor before the holidays to give the American people, consumers, confidence again, because this is a mess. Thank you, Mr. Chairman.
G
Greg Walden1:03:58
Thank you very much. The gentleman's time has expired. The chair now recognizes the gentleman from Mississippi, the vice chairman of the subcommittee, for five minutes.
C
Congressman from Mississippi1:04:07
Thank you, Mr. Chairman. Mr. Smith, thank you for being here to testify today. In your written testimony, in response to some of the chairman's questions, you stated that you were informed of suspicious activity on July 31st by your Chief Information Officer, and went on to discuss that. And you said, 'I certainly did not know that personally identifying information, PII, had been stolen or have any indication of the scope of the attack.' Did you ask him if there had been any personal identifying information that had been obtained?
R
Richard Smith1:04:43
Congressman, at that time I was informed it was a dispute portal document. A dispute portal document is something that typically houses – if a consumer is disputing with us, they've paid off a utility bill, he or she may take a picture of the utility bill. So at that time, that was a conversation.
C
Congressman from Mississippi1:04:50
Not to interrupt, but my question was: did you ask if any PII had been accessed?
R
Richard Smith1:04:53
No, I did not.
C
Congressman from Mississippi1:04:56
Were you made aware at that point of the Apache Struts patch?
R
Richard Smith1:04:59
No, sir, I was not.
C
Congressman from Mississippi1:05:01
Had you had any meetings with your Chief Information Officer or your security department about any of this issue prior to July 31st?
R
Richard Smith1:05:04
No, Congressman, I did not.
C
Congressman from Mississippi1:05:07
Had you had any meetings with them about any other security information during that time, from March until July 31st?
R
Richard Smith1:05:12
Oh yes, we would have routine meetings, security reviews. How often do you have those? Common due process would be at least quarterly.
C
Congressman from Mississippi1:05:18
And why did you not have this discussion come up? And did you have – obviously that's more than a quarter, so how many meetings did you have between that time of March 8th until July 31st with your security team?
R
Richard Smith1:05:26
Make sure I understand your question. Why didn't – no, how many meetings did you have during that time from March 8th until July 31st? I don't have that information with me. If that's important, we can get that.
C
Congressman from Mississippi1:05:30
Well, how many do you remember? Do you remember any of those?
R
Richard Smith1:05:33
So normally we'd have IT reviews at least quarterly and security reviews at least quarterly, and then you'd augment that on an as-needed basis.
C
Congressman from Mississippi1:05:38
Well, with those meetings and those timelines of March 8th into July 31st, we are covering into three quarters, not a total of nine months, but you touch into three quarters of that year. And at any point in any of that, did you have any information about this going on?
R
Richard Smith1:05:42
No, sir, I did not.
C
Congressman from Mississippi1:05:44
All right. In your testimony, you indicate that the security department ran scans in March for the vulnerability but failed to identify it. Can you explain how this is possible, and why was there never any confirmation of anybody coming back and checking to see, 'Okay, we have this identified information'? There was a failure in someone on the team to identify that it was being used, that the software was even being used. Was there no one coming in to verify that? Do you have any outside person prior to the ones that you hired to look at this?
R
Richard Smith1:05:49
Congressman, we get notifications routinely. The IT team, the security team, they apply applications. This individual, as I mentioned earlier, did not communicate to the right level to apply the patch. The follow-up was as you mentioned.
C
Congressman from Mississippi1:06:01
You said 'this individual,' so you had one person responsible for this?
R
Richard Smith1:06:04
There's an owner of the patch process. There's a communication that comes out from security, it's a broad-based communication. Once they receive notification from a software company or in this case DHS, they notify appropriate people. Then an individual who owns the patch process cascades that communication for everyone that's on your Equifax team.
C
Congressman from Mississippi1:06:12
Is there anything more important than protecting the PII of the consumers?
R
Richard Smith1:06:15
No, sir.
C
Congressman from Mississippi1:06:17
Would we identify that as the number one responsibility of the company and everybody in your company?
R
Richard Smith1:06:20
We have for years, sir. Yes.
C
Congressman from Mississippi1:06:22
So it just appears obviously the job wasn't done, and we know that. And we're trying to look at this. And I know too there was an Equifax spokeswoman who said, 'We've taken short-term remediation steps and continued to implement and accelerate long-term security improvements as part of ongoing actions to help prevent this type of incident from happening again.' So we have 145.5 million people whose PII has been compromised. How many files do you have in the system?
R
Richard Smith1:06:40
Worldwide? Yes, sir. I think someone mentioned earlier, there's a public number out there of over 800 million consumers and 100 million companies, roughly.
C
Congressman from Mississippi1:06:57
And we know this breach includes some from Canada, some from the UK. Would that be fair to say even at this point?
R
Richard Smith1:07:02
Congressman, a point of clarification. There was some data that we had on, I think, 7,000 Canadians in the U.S., so the data was in the U.S. same environment. We had some data on UK citizens also in the U.S. That piece is still under investigation.
C
Congressman from Mississippi1:07:14
You know, my home state of Mississippi has three million people. Three million people. Almost 1.4 million files have been breached in my state. That's if you take away people that are minors who don't have a file yet. Almost my entire state is going to be impacted. So this is a travesty. It's something that was preventable, we know. And so saying that we want to protect what goes forward doesn't bring us a lot of comfort today. Thank you, and I yield back.
G
Greg Walden1:07:42
The gentleman yields back. The chair now recognizes the gentleman from California for five minutes.
C
Congressman from California1:07:57
Thank you very much. I thought I prepared for this committee, but I have more chicken scratch notes. I don't even know where to start. Mr. Smith, welcome to Washington. Are you currently employed by Equifax?
R
Richard Smith1:08:21
No, sir, you are not.
C
Congressman from California1:08:23
When you decided to come before this committee, were you specifically requested by name to come to this committee by this committee, or were you offered up by Equifax as the representative of Equifax to come represent Equifax before this committee?
R
Richard Smith1:08:34
I believe I was asked specifically to come before the committee by Equifax or the committee. My understanding is by the committee.
C
Congressman from California1:08:43
Okay. Apparently the committee asked for the CEO at the time, and at that time you were still the CEO, but you're no longer the CEO. Did you inquire as to why the current CEO or interim CEO didn't come before this committee?
R
Richard Smith1:08:56
I did not. But I felt personally it was my obligation. The breach occurred under my watch, and as I said in my written testimony and my oral testimony, I ultimately take that responsibility. So I thought it was important that I be here.
C
Congressman from California1:09:14
Thank you. I get the picture. On August 31st – excuse me – on July 31st, you were notified of the suspicious activity that eventually, as we now know, is a 145.5 million person breach. Was it July 31st? Was it?
R
Richard Smith1:09:20
Yes, Congressman. It was a brief interaction, verbal interaction. Yes, you just referenced it as an answer to another one of my colleagues' questions. On that – on August 31st he received some kind of email referring to the possible breach.
C
Congressman from California1:09:27
A point of clarification. I was notified on the 31st of July by the Chief Information Officer, Dave Webb, in a very brief interaction that this portal seemed to have a suspicious incident. There was a communication trail internally between others that also referenced that I was aware of this incident through my interaction with Dave Webb. So that trail was not that written trail was not directed to you, you were just mentioned in that trail that you had been verbally notified.
R
Richard Smith1:09:48
That's my recollection.
C
Congressman from California1:09:50
Okay. Mr. Chairman, is it appropriate for this committee to ask for that trail of documents?
G
Greg Walden1:09:56
Well, that's for our counsel, but I'd say...
C
Congressman from California1:10:00
Okay, well if it's appropriate, Mr. Chairman, what I would like is for my office and this committee to receive copies of that trail that has been referenced more than once to some of our questions here on this committee, on this congressional committee. It's come to my attention that several people are no longer with the corporation. You're not officially with the corporation anymore. The CIO at that time is no longer the CIO of the corporation of Equifax. That is correct. And then there's another higher-up that is no longer the chief security officer. Okay, chief security officer. However, the then John Kelly, chief legal officer, was the chief legal officer at that time but still is currently the chief legal officer. Correct? That is correct. Okay. Apparently the chief legal officer, between July 29th and August 1st, went to outside counsel and hired outside counsel. Who? Correct?
R
Richard Smith1:10:45
No, Congressman. What occurred on August 2nd is the chief security officer reached out to a forensic expert, cyber expert, and outside counsel, King & Spalding, and she engaged them at that time.
C
Congressman from California1:10:56
Okay, thank you. When executives at Equifax want to sell stock, they need to get the chief legal officer to sign off?
R
Richard Smith1:11:04
Yes, correct, Congressman. There's a protocol that requires the general counsel of Equifax to approve that sale.
C
Congressman from California1:11:10
Okay. And John Gamble, Joseph Loughran, Rodolfo Ploder – they're all high-ups with Equifax. They apparently sold stock on or about August 1st or 2nd in the amount of approximately $1.8 million, give or take. So they had to get an okay from John Kelly before they did that. Correct?
R
Richard Smith1:11:18
That is correct, sir.
C
Congressman from California1:11:20
Okay. And apparently they did get the okay?
R
Richard Smith1:11:22
Yes, that's my understanding.
C
Congressman from California1:11:24
Okay. And you were the CEO at the time that they sold that stock, and I have no step in that, I get it. Yes, I'm referring to John, but you were the CEO at the time. Thank you, Mr. Chairman. Just a little bit latitude on my time, just a little bit, please. What I would like to request of you, Mr. Chairman, and also the ranking member, Ms. Schakowsky, that we ask for a specific hearing of this committee where we get John Kelly, chief legal officer, who was then the chief legal officer of Equifax and is currently still the chief legal officer – hopefully when we get him here he will still have that title. I'm a bit disturbed that we are, the Congress holding a hearing, and that Equifax has before us someone who no longer works for them. Thank you very much, Chairman. I hope that we can ask for that hearing where we have John Kelly, the chief legal officer, before us. Thank you very much.
G
Greg Walden1:11:45
Gentleman's time has expired. The chair now recognizes the former chair of the full committee, the gentleman from Michigan, for five minutes.
C
Congressman from Michigan1:11:53
Well, thank you, Mr. Chairman. Mr. Smith, every family watches over their financial data with great concern. It impacts their daily life – whether it's going to get a mortgage, a loan, a car – they have to have that credit score, it gets in often even a job. So they view that data as it relates to them as very, very private, and they want it to be secure. Here is an Equifax credit report for somebody that I know. It's a hundred and thirty-one pages long. Unbelievable in terms of the data that has been collected on this particular individual. I would guess that most individuals have no clue that there's that much data that's been assembled on their own personal family account. Now, you said earlier that the data was compromised. So a question that I have to ask is: does that word 'compromise' include the word or the term 'manipulated'? Are those folks who broke into that account able to actually change the accurate data that might be reflective of their own personal story? Could that be changed?
R
Richard Smith1:12:22
Congressman, I understand your question. The database was attacked by criminals, that we know. Forensic experts that we engaged in this case, Mandiant, has led us to believe that there's no indication the data left behind has been manipulated.
C
Congressman from Michigan1:12:35
Now, one of the things that's in this report – any credit report – is you verify the income of that individual to make sure that it's accurate. And as I understand it, and I go from personal experience, when one goes to get a loan, whether it's a mortgage or a car, often one of those little boxes that you check is that you are allowing permission to look at that tax return of the individual. Is that not correct? Regardless of – I was a self-employed income, regardless of automated underwriting findings, when self-employed income is used to qualify, the following documentation is required: most recent two years of their individual federal tax returns with all schedules, and W-2s and K-1s, most recent two years business returns, IRS forms 1120, 1120S, 1065s in which the borrower has ownership interest at 25% or more, and a complete and signed IRS form 4506-T is required for every borrower on the loan application. Tax transcripts validated from the IRS are required for each year documented in the loan file. So the question is: if that is collected, is a bad actor actually able to use the personal information stolen from this report to then perhaps file a false tax return come the first of the year?
R
Richard Smith1:13:22
Congressman, thanks. I think I understand your question. A couple points of clarification. A credit report does not contain employment and income information. There are many lenders that will ask you as a consumer when going to get a loan to validate your income, and there are many means, as you alluded to in your readings, as to how you might do that. But the credit report does not contain employment income data. Number two, the unfortunate criminal hack that we referred to this morning in written testimony and press release over the past month or so – it was clear to say it did not include that credit report information that you just picked up there. It was limited to, nonetheless a large number, but limited to an environment we call a consumer dispute portal, not the credit file itself.
C
Congressman from Michigan1:14:19
Last question I have is: how did you know? I mean, how? We've had a lot of hearings, a number of them classified, breaches made into Department of Energy, utilities, a whole number of different major players where hackers are coming in trying to break and penetrate daily. What tripped these guys up? How did you identify that in fact a breach had been made? What was their mistake?
R
Richard Smith1:14:58
Congressman, there's a piece of technology called a decrypter. And there was a decrypter that allowed us to see some of the data. And once we saw the data, that's what started the conversation earlier in the testimony here. That's when we saw the suspicious data and we were able to shut off the portal at the end of July.
C
Congressman from Michigan1:15:21
You're back by time. Thank you very much. The gentleman yields back.
G
Greg Walden1:15:25
And the chair now recognizes the gentlelady from Michigan for five minutes.
C
Congresswoman from Michigan1:15:34
Thank you, Mr. Chairman. Mr. Smith, I first want to say we appreciate your coming in to testify today. We spent a lot of time talking today about the what, the when, the where, and the whys of this breach, and I agree with all of my colleagues that we need to be expressing extreme displeasure. But I want to ask a few questions about where we go from here, because I hope this has awoken the American consciousness about privacy and credit, that they need to be paying far more attention. This breach is different than most, not only the scale of those affected but the type of information taken. In the past, folks usually just changed your passwords, maybe you got a new credit card, and that was it. It was an annoyance but had no real impact on your life. That's not so simple when it's your social security number or other personal information. You can't change your social security number, and I can't change my mother's maiden name. This data is out there forever. Clearly something needs to be done. We can all sit here and talk about what went wrong, but we are doing the public a disservice to not at least begin the discussion on how to improve data security. That's why I am a proud cosponsor of Representative Schakowsky and Ranking Member Pallone's bill. It's a good first step that needs to be given serious consideration. And I am also introducing the Data Protection Act of 2017. Whatever path we choose going forward, it's important that we take action on the topic and that all American consumers pay attention. Now, I'd like to ask a few questions. Nobody's asked this question yet, so just a quick yes or no: have you or anyone on your team seen signs that the attackers were backed by a nation-state?
R
Richard Smith1:17:30
Congresswoman, we've engaged the FBI at this point. That's all I'll say.
C
Congresswoman from Michigan1:17:36
I don't think it's all the same, but thank you. To your security department: they blocked the suspicious traffic you mentioned in your testimony. Did anyone from your team or outside companies venture beyond the perimeter of your network to attempt to locate where they came from?
R
Richard Smith1:17:56
Congresswoman, yes, we have the ability to track the IP address of the criminals. But as you know, finding a location where the IP address is does not necessarily tell you where they're from. It's easy to set up IP addresses anywhere in the world.
C
Congresswoman from Michigan1:18:12
I think we all care about this, but I want to move to this other topic. I share your belief that placing control of access to consumers' credit data should be placed in the hands of the consumer. But most people have no idea that Equifax was even holding their data. I unfortunately learned a long time ago because this isn't the first data theft. Doris and I both were part of something else where they got our social security numbers and mothers' maiden names. It's one thing to take steps to mitigate damages after breaches occurred, but going forward we must give consumers the chance to protect themselves before a breach happens. Do you believe that consumers can take reasonable steps to secure their identity and information if they don't even know who has it?
R
Richard Smith1:19:03
Congresswoman, I think we can help. I think we can help by the announcement of this offering to all Americans the ability to lock and unlock your credit file for life for free. There needs to be greater awareness. I understand your point clearly. I think by making this available to all Americans is one step in doing that.
C
Congresswoman from Michigan1:19:24
So I was just actually even educating my colleagues up here about Credit Karma, and they were stunned by how easy it was with too little factoids to suddenly unleash the amount of money they had in every one of the credit card companies, what any data inquiries have been in all of the different factors. I have a couple, and I think most people don't understand that it's not just you but Experian and TransUnion who are also collecting this data. Why do consumers have to pay you to access their credit report? Why should that data not be free?
R
Richard Smith1:20:05
Congresswoman, the consumer has the ability to access the credit report for free from each of the three credit reporting agencies once a year. And you combine that with the ability to lock your credit file for life for free, again as a step forward.
C
Congresswoman from Michigan1:20:23
Well, I'm running out of time, but like my colleague over here, when you find mistakes – which a number of us have, and we're luckier than 99.9% – it's very difficult to fix. And when you do fix it, you still have to pay. I think we need a longer debate about who owns this data and how we educate the American people. Thank you, Mr. Chairman.
G
Greg Walden1:20:45
Thank you very much. The gentlelady's time has expired. The chair now recognizes the gentleman from New Jersey for five minutes.
F
Frank Pallone1:20:50
Thank you, Mr. Chairman. Good morning to you, Mr. Smith. Criminals perpetrated this fraud. Is it possible that these criminals are from another country?
R
Richard Smith1:20:58
Congressman, it's possible. But at this time, it's possible.
F
Frank Pallone1:21:00
Number two: is it possible it's the government of another country? You mentioned to the congresswoman a few minutes ago, we've engaged the FBI, they'll make that conclusion. Do you have any suspicions in that regard, either persons from other countries or the government of another country?
R
Richard Smith1:21:12
Congressman, at this time I will defer. We have the FBI involved.
F
Frank Pallone1:21:15
Yes, I know we have the FBI involved. Do you have an opinion to the two questions I've just asked?
R
Richard Smith1:21:18
I have no opinion.
F
Frank Pallone1:21:20
You have no opinion. The stock that was sold by your colleagues, Mr. Gamble, Mr. Loughran – I hope I'm pronouncing that right – Mr. Ploder. As I understand, that stock was sold on August 2nd. Is it usual that executives of a mature company, not a company that has just come onto an exchange, is it usual that significant amounts of stock are sold?
R
Richard Smith1:21:32
Congressman, a few points of clarification. The stock was sold on the first and the second. I said the second, the first was – I think the first date it was sold. Yes, it's not unusual for stock to be sold at the end of a quarter, as we have our earnings call. The window opens up. We encourage those who are going to sell to sell as early in the window as possible. The window is open for about 30 days. The sales early in the window as possible, and that's what occurred here.
F
Frank Pallone1:21:50
Yeah, you believe that this stock was sold merely as a matter of course, as would be true in any other quarter?
R
Richard Smith1:21:53
Yes.
F
Frank Pallone1:21:54
You do not believe it was based upon knowledge known by these gentlemen related to the breach?
R
Richard Smith1:21:57
Congressman, I've known these individuals – some of them up to 12 years. They're honorable men, they're men of integrity. They followed due process, they went through the clearance process to the general counsel. I have no indication that they had any knowledge of the breach at the time they made the sale.
F
Frank Pallone1:22:08
Did you have knowledge of the breach at that time?
R
Richard Smith1:22:10
I did not, sir.
F
Frank Pallone1:22:12
Weren't you warned well in advance of this that there was suspicious activity?
R
Richard Smith1:22:15
I was notified on July 31st in a conversation with the Chief Information Officer that there was suspicious activity detected in an environment called the web portal, the consumer dispute. No indication of a breach. That was prior to the sale of the stock. Is that accurate? 31st of July, there's no indication of a breach at that time.
F
Frank Pallone1:22:28
From my perspective as a layman, the difference between a breach and suspicious activity is not one that I believe is particularly relevant. A breach might have technical connotations to it, but certainly you were aware of untoward activity prior to that date. Is that accurate?
R
Richard Smith1:22:40
No, Congressman, it is not. On the 31st, we had no indication the documents were taken out of the system, what information was included. It was very early days. It took the forensic experts, as I mentioned earlier, from then until the 24th to start to develop a clear picture, and that picture's still changed. The 24th – we heard just last night with the additional announcement. Many calls have been received by Equifax at your call center since September 7th. Do you know how many calls have been dropped or missed due to staffing shortages or other issues?
F
Frank Pallone1:23:05
Congressman, I don't have the exact number, but as I...
R
Richard Smith1:23:08
The transcript ends here.
In my opening testimony I apologized for that startup. It was overwhelming in volume. I think I mentioned over 400 million U.S. consumers coming to a website in three weeks. We went live in a very short period of time with call centers. Our two larger call centers were taken down in the first few days by Hurricane Irma. The team is committed and was committed to make the experience better for the consumer, and I'm told that each and every day the process is getting better.
C
Congressman1:31:02
On August 22nd you notified a lead director, Mr. Fiedler I hope I'm pronouncing that right, of the data breach, and the full board was informed later, I believe two days later. Why was there nearly a week between August 17th and August 22nd before members of the board were alerted?
R
Richard Smith1:31:27
Congressman, the picture was very fluid. We were learning new pieces of information each and every day. As soon as we thought we had information that was of value to the board, I reached out to the lead director, as you said, Mark Feidler, on the 22nd. Convened a board meeting on the 24th, had a second board meeting on the 25th. I had subsequent board meetings with him, if not daily in many cases, through as recently as last week.
C
Congressman1:31:52
Thank you. My time has expired, Mr. Chairman.
G
Greg Walden1:31:54
Thank you very much. The gentleman's time has expired, and the chair now recognizes the gentlelady from California for five minutes.
J
Jan Schakowsky1:32:03
Thank you, Mr. Chairman, and thank you, Mr. Smith, for appearing here today. As many of my colleagues have highlighted, the events that led to this data breach and the actions Equifax management took after the fact are very upsetting. It seems that many Americans are in a place of breach fatigue, but this latest event that potentially impacts nearly half of all Americans should light a fire under every single member here, and I think you've noticed that it has lit a fire. We cannot follow the same script after the next inevitable data breach. That's one of the reasons why I am also supporting Congresswoman Schakowsky's Secure and Protect America's Data Act. And it's not as if this type of legislation is unprecedented. 48 states have implemented laws that require consumers to be notified of security breaches, and I'm pleased that my home state of California was the first state to pass this kind of notification law in 2002. Today, if California residents' personal data is hacked, state law requires that they are notified in the most expedient time possible and without unreasonable delay. We must act to ensure that all Americans are subject to protections like this at the federal level. Mr. Smith, because Equifax without doubt has the information of many California residents, the company is subject to the California data breach notification law. Can you please describe to me how Equifax complied with the state law? Were California residents notified of the breach as required?
R
Richard Smith1:33:35
Congresswoman, I don't have the specific knowledge of the California law. I can tell you though that we worked as a team, including with our counsel, to help ensure what we were doing was right for the consumer in the most expedient manner as possible. So we are aware of the requirements of the different state laws. I just don't have the specific knowledge as it relates to the state of California.
J
Jan Schakowsky1:34:00
So you also don't know, because the law also requires Equifax to submit a copy of the breach notification to the California attorney general. You don't know whether this was done?
R
Richard Smith1:34:11
Congresswoman, I do not. But we can have our team follow up through staff if that would be helpful.
J
Jan Schakowsky1:34:17
In the context of this breach, if data that you hold is about me, do I own it? Do I own my data?
R
Richard Smith1:34:29
Would you please repeat the question?
J
Jan Schakowsky1:34:31
In the context of this breach, if the data that you hold is about me, do I own it?
R
Richard Smith1:34:38
Congresswoman, we are part of a federally regulated ecosystem that has been around for a long time, and it's there to help consumers get access with consent to credit when they want access to credit.
J
Jan Schakowsky1:34:56
Well, can you explain what makes data about me mine compared to what makes it someone else's?
R
Richard Smith1:35:02
The intent, if you will, of the solution we have recommended, implemented, and are going live with in January of 2018 is in fact to give you, as the consumer, through this lock product for life for free, the ability to control who accesses your personal information and who does not.
J
Jan Schakowsky1:35:24
So at that point in time, you believe that I own — I can say I own my data, is that right?
R
Richard Smith1:35:27
You'll have the ability to control who accesses and when they access your data.
J
Jan Schakowsky1:35:36
Okay. Could I ask you some further questions following along to what others have asked about credit locks and credit freezes? Now, limiting access to credit even for a short amount of time can have real financial consequences, especially for low-income populations. How quickly will a file be able to be locked and unlocked, and how will you ensure that speed?
R
Richard Smith1:36:00
Congresswoman, thank you for that question. That is a great advantage of the product that we're offering for free versus the freeze, which came about in 2004 out of regulation, and their states dictate how quickly you can get access to freezing and unfreezing your file. Oftentimes that can take days if not weeks because we're mailing data back and forth to the consumer. In this case, the intent is in January of 2018, on your iPhone, you can freeze and unfreeze your file instantly at the point you want it locked and unlocked.
J
Jan Schakowsky1:36:39
So, and I recall that one of my colleagues asked whether a credit lock is the same thing as a credit freeze, and you said it was. Is that correct as far as protection to the consumer?
R
Richard Smith1:36:49
Congresswoman, it is as far as ability to lock or unlock and freeze or unfreeze. The lock is far more user-friendly.
J
Jan Schakowsky1:36:58
Okay. So you currently offer a credit lock product now, and you plan to offer this other one for free starting end of January. And can you describe for me why you consider that — would a lock be more economical for you, or would a freeze be? I'm trying to get the sense of the difference because I think there is a difference here.
R
Richard Smith1:37:31
Yes, if I may one more time to try to clarify. As far as protection, they are the same. The lock that we offered to consumers on September 7th gives you the same level of security you'd get from a freeze or from the product that's going out in January. The difference is today's lock is browser-enabled; January's lock will be an app on an iPhone. And secondly, it'll be instant on, instant off, versus the freeze.
J
Jan Schakowsky1:38:05
I've got more questions but I know I'm out of time. Thank you.
G
Greg Walden1:38:09
Thank you very much. The gentleman from Illinois is recognized for five minutes.
C
Congressman from Illinois1:38:13
Thank you, Mr. Chairman, and sir, thank you for being here today. This is obviously a huge issue. 145 and a half million people affected by this data breach — it's nearly half of all Americans. That's a failure on multiple levels. It's a failure to keep consumer personal information secure, it's a failure to appropriately respond to a breach, and a failure to notify the public and much more. My constituents and the American people need not just answers, but they want assurances that they're not going to be financially ruined by this. I do want to make a quick point. Mr. Luján asked you if the people that would be harmed by this would be made whole, and you made a statement — and I understand there's probably some legal and technical reasons for this — but you said, 'I don't know if consumers are harmed.' We are harmed. I just want to make the point that the idea that people are not harmed is ludicrous. Of course they're going to be harmed. Even if there's no financial harm that comes to them, just having this information exposed is a massive deal. But I fear that we're going to see bigger repercussions from that. But let me say now, Mr. Smith, I was surprised to find out that Equifax initially included a requirement that consumers consent to a mandatory arbitration clause. Why did that happen? Why was that at the beginning part of the rollout?
R
Richard Smith1:39:30
Congressman, thank you for that question. I want to clarify. The product offering that went live on the service offered on the 7th — it was never intended to have that arbitration clause apply to this breach. It was a standard boilerplate clause as a part of a product. As soon as we learned that boilerplate term was applied to this free service — I think it was within 24 hours — we removed that and tried to clarify that that was a mistake, one of the mistakes I alluded to in my oral testimony about the remediation product on September 7th.
C
Congressman from Illinois1:40:03
So does Equifax require consumers to consent to arbitration with respect to any of its other products? And if not, is that information prominently disclosed to the consumer?
R
Richard Smith1:40:14
Not as it relates to the breach, Congressman.
C
Congressman from Illinois1:40:17
Well, the question is, what about any other products? Do you require consent to arbitration?
R
Richard Smith1:40:22
Some of the consumer products we have — there's an arbitration clause in there. It's a standard clause.
C
Congressman from Illinois1:40:28
What's the reason for that?
R
Richard Smith1:40:31
I don't have that answer other than it's a standard clause.
C
Congressman from Illinois1:40:34
Hopefully you can get that to me. That'd be good. Your press release indicates that the company found no evidence of unauthorized activity on Equifax's core consumer or commercial credit reporting databases. What are Equifax's core consumer and commercial credit reporting databases, and how are they distinct from the databases containing personal information that was subject to the unauthorized theft?
R
Richard Smith1:40:56
Congressman, the area that was impacted here was a consumer dispute portal, where consumers come in and they dispute activity with us. That is separate from — as a few congressmen had talked about — the credit file on their hand. That is separate from the core credit data that consumers have in our database. So in essence, where there are 145.5 million people that at one point had disputed credit issues — that was the portal they used. They could have been in that portal for multiple reasons, and we also by regulation have to keep data for extended periods of time, in some cases seven plus years. So it's a lot of data for a lot of years, but it's outside of the core credit file itself.
C
Congressman from Illinois1:41:45
Which company databases were accessed? And why wouldn't you consider that, maybe this is a change now after this, why wouldn't you consider that to be part of the core consumer and commercial credit reporting databases?
R
Richard Smith1:42:00
It's just the way we define it. The credit file itself is housed and managed in a completely separate environment from a database that consumers would come into directly. The core credit file itself is largely accessed by corporations and companies that we deal with, versus consumers.
C
Congressman from Illinois1:42:16
Okay, so I just want to make sure — and you have to forgive me, I'm not an IT expert — so to get 145 million people's records in only the dispute database, I guess I'm trying to figure out if you didn't really answer the question. Were there 145 million people that have disputed at some point in time, half of Americans? Or was there another entry somehow through that that went into other information? Maybe I just don't understand the IT part of this.
R
Richard Smith1:42:42
The only entry was through the consumer dispute portal, and that is a completely separate environment from the credit file itself. We also, as you might recall, have a lot of data for small businesses in America in that environment, which is part of the definition you were alluding to, and it was not compromised either.
C
Congressman from Illinois1:43:05
Okay, and lastly, are your core consumer or commercial credit reporting databases encrypted?
R
Richard Smith1:43:10
We use many techniques to protect data: encryption, tokenization, masking, encryption in motion, encryption at rest. To be very specific, this data was not encrypted at rest.
C
Congressman from Illinois1:43:25
Okay, so this wasn't, but your core is?
R
Richard Smith1:43:28
Some, not all. Some data is encrypted, some is tokenized, some is in motion, some is masked. There are varying levels of security techniques that the team deploys in different environments around the business.
C
Congressman from Illinois1:43:40
Okay, thank you, sir. I yield back.
G
Greg Walden1:43:44
Thank you very much. The gentleman yielded back. The chair now recognizes the gentleman from California for five minutes.
C
Congressman from California1:43:51
I thank the chair for holding this hearing. Mr. Smith, it's my understanding that the compromised information was due to an unpatched vulnerability in the web application framework Apache Struts. Besides the company's online consumer dispute resolution portal, does Equifax have any other portals that use Apache Struts?
R
Richard Smith1:44:15
No, sir. This was the environment that had deployed Struts.
C
Congressman from California1:44:20
All right, that was a simple answer. You might need to restart my time. In addition to Equifax's credit monitoring and reporting services, the company has Equifax for Business offerings and in this capacity operates as a data broker. As a part of these services, the company collects large amounts of data about consumers without consumers having any knowledge of this happening. Was this information compromised in the breach?
R
Richard Smith1:44:50
I think I understand your question. Could you repeat that one more time, please, so I get it right?
C
Congressman from California1:44:55
Okay. You're familiar with the Equifax for Business offerings? Yes, we do have product offerings and solutions for small businesses, medium-sized businesses, and large businesses across the country, correct?
R
Richard Smith1:45:07
Right. Was information from Equifax for Business also compromised in the breach?
C
Congressman from California1:45:12
No, Congressman, it was not. It goes back to the question earlier. As part of what we call our core accredited data, it was not compromised.
R
Richard Smith1:45:19
Well, in your testimony you noted, 'Throughout my tenure as CEO of Equifax, we took data security and privacy extremely seriously and devoted substantial resources to it.' Could you tell us about what investments Equifax made in cybersecurity during your tenure?
C
Congressman from California1:45:37
Yes, Congressman, I can. When I came to the company 12 years ago, we had virtually no focus on cybersecurity at that time. Cybersecurity was not as sophisticated as it is today. We've gone from that environment to a team now of over 225 professionals focusing each and every day on security around the world.
R
Richard Smith1:45:58
So what time frame is that?
C
Congressman from California1:46:01
That was from the time I started, 12 years ago.
R
Richard Smith1:46:05
So you say that you hired up to 250 personnel, I believe?
C
Congressman from California1:46:07
The team did. I didn't hire them, sir, but we now have a staff of 225 cybersecurity experts around the world. We made substantial investments over that time frame. In the last three years alone, we've invested approaching a quarter billion dollars in security.
R
Richard Smith1:46:29
There's an IBM benchmark that says financial services companies tend to be best in class, spending somewhere between 10 and 14 percent of their IT budget on security. What about when they were notified of the vulnerability in the Apache Struts system days before the attack occurred?
C
Congressman from California1:46:53
Yes, we were notified by the Department of Homeland Security in March of 2017.
R
Richard Smith1:46:59
And the attack occurred after the notification?
C
Congressman from California1:47:03
Yes.
R
Richard Smith1:47:05
So was there a human failure? I mean, how could 250 professionals that are designed and hired for that purpose let a breach like that happen after they were notified?
C
Congressman from California1:47:16
As I said in my oral testimony, the notification comes out. We had a communication process in place. I described it as a human error where an individual did not ensure the communication got to the right person to manually patch the application. That was subsequently followed by a technological error — a piece of equipment we use which scans the environment looking for that vulnerability did not find it.
R
Richard Smith1:47:51
That seems like a lack of competence or a professional error of some kind. Would you call it that?
C
Congressman from California1:47:56
I described it as a human error and a technology error, and I apologize for that, but that is what happened.
R
Richard Smith1:48:09
Okay, moving on. Do you believe that the FTC has an important role in protecting consumers from future data breaches? How much of a role should the FTC be playing at this point given what's happened?
C
Congressman from California1:48:21
I think there's a role for the business to do more, industry to do more. We talked about earlier this concept of offering the consumer the ability to control their data and lock and unlock when they so choose. And if there's particular legislation that arises out of this horrific breach, I'm sure you'd find the management of Equifax and the industry willing to work and cooperate with the regulators.
R
Richard Smith1:48:49
Well, the reason I'm asking is the Federal Trade Commission is an enforcement body but it doesn't have any rule-making authority. Do you think the FTC should have rule-making authority? Do you think it would have made a difference? Do you think it will make a difference in the future? Or do you have an opinion?
C
Congressman from California1:49:03
I have no opinion.
R
Richard Smith1:49:06
Well, my final question is, how long will individuals be vulnerable to identity theft problems due to this breach?
C
Congressman from California1:49:13
We offered five different individual services, as you may or may not be aware, effective September. One is the ability to monitor your credit files from all three of us for free, and others to lock your file, another is dark web scanning.
R
Richard Smith1:49:32
That doesn't answer my question. How long are we going to be vulnerable? How long are we — our Social Security numbers are out there. This is forever, right?
C
Congressman from California1:49:42
Unfortunately, the number of breaches around Social Security numbers has been on the rise, as you know, and many even this year. So there's another thought: do we think about how secure really is an SSN, and is that the best identifier for consumers going forward?
R
Richard Smith1:50:00
Thank you, Mr. Chairman.
G
Greg Walden1:50:01
Thank you very much. The gentleman's time has expired. The chair now recognizes the gentleman from Kentucky for five minutes.
C
Congressman from Kentucky1:50:08
Thank you, Mr. Chairman. Thank you for being here, Mr. Smith. We appreciate you being here to testify. There's a medical hearing going on upstairs, so I've been back and forth, so I'm trying not to duplicate a question. When I was here earlier, a lot of people have asked, and a lot of us wondered: July 31st was the suspicious activity, and then it seemed the notice to the board was about three weeks later, August 24th and 25th. So not to repeat, I know I heard you say that it was suspicious activity and therefore you didn't realize it was a breach, and then the action took place three weeks later. Looking back now, knowing how colossal this is and how big it is, would you have done different? From July 31st to August 24th, what would you have done different that didn't happen or Equifax didn't do?
R
Richard Smith1:50:56
Congressman, that's an appropriate question. To be honest, time for reflection will come. There's been no time for reflection. This has been a team of people, including myself, working around the clock for the last six to eight weeks, trying to understand the forensics, trying as best we could to stand up an environment to offer consumer services to protect themselves. There will be an opportunity, I'll have time to catch my breath and reflect, but I have not had a chance to do so now.
C
Congressman from Kentucky1:51:30
I appreciate that. Well, it was 1.9 million Kentuckians exposed in this hack. One of the questions we have about the process that Equifax underwent to help people determine that — one was setting up a new website, not just a portal within your website, for consumers to visit. Was that an appropriate response? I know there were some issues with getting onto the website. Were you part of the deliberation? Why did you choose to set up a new website that seemed to cause issues, as opposed to just doing a portal on your current website?
R
Richard Smith1:52:03
Congressman, good question. It was strictly due to the sheer volume of incoming visitors that we had expected. The traditional website that we'd use to interact with consumers services a total of maybe seven or eight hundred thousand consumers at any given point in time over a period of time. I mentioned in my opening comments earlier, this new microsite as we call it that we set up had the capacity to surge to much higher levels. We had some 400 million — I think it was 420 million consumers come to visit us in the first three weeks on that website. Our traditional Equifax website could not have handled that volume day one.
C
Congressman from Kentucky1:52:46
Okay. According to reports, many consumers were unable to determine with certainty if their information was breached. So why was Equifax unable to provide clarity or certainty of whether an individual's information was breached when you went to the website?
R
Richard Smith1:53:00
Congressman, when you typed in six of your nine digits of your Social Security number, if it was likely that you were breached, it would say something along the lines of 'It looks like you may have been compromised or breached,' as opposed to 'It's definitely you've been breached.' That's because it was six digits versus nine. But the point is, we offer this service — these five different services — to every American. It didn't matter if you were compromised or not. Every American was offered the same services.
C
Congressman from Kentucky1:53:35
So, and just going forward, because we have to also do an analysis of what we're going to do as a legislative body to protect the American people. What your business does and what people in your business do are important. It's when you can sit down at a car dealer — I think you kind of mentioned earlier — walk away with a car that afternoon because somebody can check that you're creditworthy. So having those types of services available is important. So what steps is Equifax doing to rebuild the confidence? People aren't confident that their information is flowing out there, but the ability to access credit almost immediately if you have the proper credit is something that your services provide. But the risk is having all that information in one place, plus the convenience of what your type of business serves. So what are you doing to rebuild, or how can people be confident that this can go forward?
R
Richard Smith1:54:31
Congressman, that's a really good question. We're a 118-year-old company, and we've done a lot of great things for consumers over those 118 years. We take being a trusted steward seriously. So step one is to make sure we think more holistically and broadly about steps we should have taken to make sure we're more secure today than we were at the time of the breach. Second thing we can do is offer these services to consumers that we offered on September 7th to make sure they are protected. And third is to launch this whole paradigm shift effective January of next year, which is to put the power of control of the consumer credit in the consumer's hands, not our hands.
C
Congressman from Kentucky1:55:14
Thank you. That would be helpful. I appreciate that. Now my time's expired. I yield back.
G
Greg Walden1:55:19
Thank you very much. The gentleman's time has expired. Pursuant to committee rules, we'll go with the members on the subcommittee by order of appearance, and then after that the non-subcommittee members. So the chair would recognize the gentleman from Florida for five minutes.
C
Congressman from Florida1:55:36
Thank you, Mr. Chairman. I appreciate it. Mr. Smith, one of my constituents accessed Equifax's website, equifaxsecurity2017.com, to determine if they were affected. They informed me that whether you submit your own identifying information or whether you submit a random name and Social Security number, you get the same message that you may be affected. What course of action should consumers who haven't received correspondence yet as to whether they're affected take? And if they were affected, what are the next steps?
R
Richard Smith1:56:15
Congressman, it's my understanding that those who have gone online to register and were not notified immediately — that backlog is completely drained now, if you will. So if you are trying to sign up for the service, if I understand your question correctly, you have now been notified.
C
Congressman from Florida1:56:36
Okay. I understand that Equifax currently is waiving fees to freeze and unfreeze your credit. How long is that exemption going to stay in place? Because it's so very important.
R
Richard Smith1:56:50
It is important, Congressman. We announced on September 7th the ability to lock and unlock your file at Equifax for free for one year from the time you sign up. We've also announced a product we've been working on for quite some time, effective in January of 2018, the ability to lock and unlock your file with Equifax for life for free. That'll be the next generation of the lock that we offered in September.
C
Congressman from Florida1:57:19
Okay. As CEO, what level of involvement did you have with regard to data security and data protection?
R
Richard Smith1:57:30
Obviously the buck stops with me, I understand that. Data security reported to a direct report of mine, my general counsel. I would have active involvement with my general counsel and the head of security routinely throughout the year.
C
Congressman from Florida1:57:52
Okay. What responsibilities did Ms. Mauldin, the chief security officer at Equifax at the time of the breach, have with respect to data security, data protection, and data breach notification? What were her responsibilities?
R
Richard Smith1:58:10
Those were core of her responsibilities. She was the head of cybersecurity and physical security in all 24 countries we operate.
C
Congressman from Florida1:58:21
How many briefings did you have with Ms. Mauldin between March 8th and July 29th of 2017? How many briefings?
R
Richard Smith1:58:31
I don't recall. As a congressman asked earlier, there are routine meetings which we go through — security strategy, security quarterly reviews, investment decisions required for security. But the actual number of times in that time frame, I don't recall.
C
Congressman from Florida1:58:51
Okay, so say half a dozen, a dozen? That would be a guess. I would guess more than three. If it's important to the committee, we can find that information. Give me that information. I appreciate that. What responsibilities did Mr. Webb, the chief information officer of Equifax at the time of the breach, have with respect to data security, data protection, and data breach notification?
R
Richard Smith1:59:18
Directly none, sir. He was expected, obviously as the head of technology, to work closely with the head of security, but the security function was a separate function. But you can't do security without IT, you can't do IT without security.
C
Congressman from Florida1:59:33
How many briefings did you have with Mr. Webb between March 8th and July 27th of 2016? If I may just clarify, March 8th is when the CERT came out saying there was a vulnerability in Apache Struts. I was not even notified to put in perspective that there was an incident. I didn't know what the incident was until July 31st. So the number of meetings I would have with Dave Webb would not have been related to this incident.
R
Richard Smith1:59:59
All right. Thank you. I yield back.
C
Congressman from Florida2:00:06
Thank you very much. The gentleman yields back. The chair recognizes the gentleman from Indiana for five minutes.
G
Greg Walden2:00:08
Thank you, Mr. Chairman. Thank you for being here. And again, I was at the health subcommittee hearing too, so I'm back and forth. Sorry about that. But is it possible people who never signed up or used Equifax directly could have been impacted by the breach?
C
Congressman from Indiana2:00:15
Yes, Congressman. Okay, so how does Equifax get the information on people who've never directly associated with Equifax at all? I mean, I'm not familiar with that.
R
Richard Smith2:00:39
We get it from banks, telecommunications companies, credit card issuers, and so on and so forth. Just like when you go to apply for a loan, they send you the information because they want to get the information on my credit rating, for example. Correct. As I define it, we are part of the federally regulated ecosystem that enables banks to loan money to consumers. So it's up to the banks at that point to notify the individual which credit agencies they're utilizing to assess their credit risk. Or is it up to the credit — traditionally the contributors of the data in that case, Congressman? The banks would give their data to all three. That's the benefit of the system: you get a holistic view of an individual's credit risk.
C
Congressman from Indiana2:01:21
Yeah, my point is, I guess, because a lot of people I talked to back in Indiana, Southern Indiana, have no idea who Equifax is, right? And many of those people have applied for home loans and other things, and matter of fact, probably at some point you have their information, but they just may or may not have been notified who sent the information to them. Probably the bank or other agency. And that's something I think is also maybe an issue — that people don't understand or have not been told who is being used to assess their credit risk. And hence, something like this happens, they have no idea whether or not their information has been compromised. I understand your point. Yeah. I also have a lot of constituents in rural and lower income areas that may or may not have access to the internet and Wi-Fi. The penetrance of that — it's interesting depending on where you are. People who actually have Wi-Fi and the internet is not as high as you might think in rural America. But some of those people still have probably applied for loans and other things where their information could have been acquired by your company. How are you notifying all of those people other than saying that you have a website? You may have already answered that, and I apologize if you have, but that's important because again, the penetrance of people having access to the internet may not be as high as you think when you come out to rural Indiana and other areas.
R
Richard Smith2:02:56
Coming from Indiana, I understand Indiana. Congressman, we have set up the website that you mentioned, and a press release across the country. We've also set up, for those who don't have access to the web or the internet, call centers. We've staffed up; we went from some 500 call center agents to over 2,700.
C
Congressman from Indiana2:03:21
So I guess that's again — I understand the call centers and all that. I knew you had done that. But I guess that's again making the assumption that people have watched the news and know that there has been a breach and that they are proactive in trying to find out whether they've been involved or not. Is there any other than passive way for them to find out? Is there anything proactive from Equifax's point of view that might notify them that their data may have been compromised?
R
Richard Smith2:03:47
Well, in many states, there are local requirements, state requirements, to take out advertisements in newspapers and so on and so forth. We follow those. One indication I did mention earlier — it may or may not help those in rural Indiana — but the visibility this has gotten is extremely high. I mentioned 400 and some odd million consumers had come to our website. So it's gotten the press, and probably after today, more people will know.
C
Congressman from Indiana2:04:17
So thank you for answering those questions. I do have, like I said, my main concern is that my constituents understand whether or not their data has been compromised and then what are their options going forward. You've outlined most of those things today. I'm not going to ask you that again. But I do think it's important to recognize that although they are important, passive ways to have people become aware of their data being compromised is one approach, but also actively informing people proactively might very well be important in certain areas of the country. Thank you. I yield back.
G
Greg Walden2:05:00
The chair now recognizes the gentleman from Texas for five minutes.
C
Congressman from Texas2:05:04
Thank you, Mr. Chairman. I apologize — we have the health subcommittee upstairs, and I appreciate that's not to take away the importance of this hearing. I want to thank you and our ranking member for setting it. We're here to discuss one of the worst and most impactful hacks that we've seen. It's a breach that was entirely preventable due to a level of negligence that in some industries may be considered criminal. The credit reporting industry is famously unforgiving, and it is an industry that helps perpetuate the cycle of poverty. Agencies like Equifax force those with lower credit scores to pay more money for loans and mortgages. Less than perfect credit scores can even result in higher rates for products that don't require credit, like our auto insurance premiums. These people have a harder time paying back. Higher interest rates make it more likely they won't be able to pay their debt back on time and will hurt their credit further. Yet Equifax and the rest of the credit reporting industry expect forgiveness for breach after breach, lobbying Congress for even less liability. When restaurants fail regular health inspections, they're routinely shut down for violations. They're shut down even if problems haven't yet occurred as a consequence of their violations. It isn't clear to me why Equifax, which is beyond that point, should be allowed to continue operating when they have failed spectacularly at their core business and endangered the public. In the next couple months, Senate Republicans may repeal the Consumer Financial Protection Bureau's arbitration rule, thus allowing companies like Equifax that put clauses in their fine print forcing individuals into arbitrary arbitration agreements instead of class action agreements where they stand a chance of being able to recover some of their losses. But it should be clear to all of us that now is not the time to roll back consumer safeguards in the financial industry. I support my colleague and our ranking member Congresswoman Schakowsky's Secure and Protect America's Data Act. I look forward to hearing what our witness has to say. Mr. Smith, ID threat protection companies have seen a big jump in business and share price since the breach of your company, including LifeLock, which has reported a tenfold increase in enrollment for their credit monitoring and other services. LifeLock has a contract to purchase credit monitoring services from Equifax, meaning that every time someone signs up for LifeLock protection from the impact of the Equifax data breach, they're involuntarily signing up for Equifax to provide those services, and Equifax makes money on that breach. What is the value of that contract that LifeLock has with Equifax?
R
Richard Smith2:07:52
Congressman, I don't recall what that is. But at the same time, those same consumers have the ability to come to us directly and get a free product.
C
Congressman from Texas2:08:07
Okay, if it's available, I hope you'd send it and share it with the committee. Mr. Smith, Equifax reportedly marketed to its business customers that 'leading lifestyle databases available commercially offer hundreds of response segments covering almost every conceivable aspect of how consumers live and what they spend their money on and what interests they have.' Can you tell me, on as granular a level as possible, what the sources are for that data for every conceivable aspect of a consumer's life?
R
Richard Smith2:08:42
Congressman, I'm not quite sure what you're referring to. We are not a data provider in the area of behavioral analytics, behavioral data, social media data. So I'm not quite sure what you're referring to.
C
Congressman from Texas2:08:57
Well, I have a lot of constituents who are concerned. For example, they say, 'Oh, I don't need to worry about this breach. I haven't applied for credit for 10 years.' But that's not always the case because these hundreds of millions who are released — maybe they bought a car 20 years ago and that data still goes forward. I assume, Mr. Smith, Equifax's customers are businesses who purchase data and credit reports on consumers. The American public is essentially Equifax's product. How many times per year on average does Equifax sell access to a given individual's credit file to a potential creditor, and how much do they make every time they sell it?
R
Richard Smith2:09:41
If I understand the question, Congressman, we take the data that is given to us by the credit ecosystem of the U.S., apply analytics to it, and then when a consumer wants credit — again, through credit card, home loan, a car — the bank then comes to us for that data, for that analytics, and we charge them for that.
C
Congressman from Texas2:10:07
Okay, well the question was, how many times does Equifax receive payment for that individual credit file? Every time, if my local car dealer contacts Equifax, they pay a fee to Equifax for that information, yes?
R
Richard Smith2:10:25
Yes, Congressman. If you as an individual want to go to that car dealership and get a loan for a car, they come to us or to our competitors, and when they take your data, access your data, we do get paid for it, correct.
C
Congressman from Texas2:10:40
The clock wasn't started right. You have about 15 seconds. I'm sorry, you have about 15 seconds. The clock didn't start on you. Okay, I thought I just had a perpetual fact. No. Mr. Chairman, I just have one more question. Of the products that Equifax is so far providing victims of the breach, do not include anything they wouldn't need if it weren't for Equifax's laxness on their data. You have made more than $69 million in 2016, and so that's the concern that this committee has, and I know we have for all our constituents. I thank you, Mr. Chairman, for your time.
G
Greg Walden2:11:18
Well, thank you very much. I appreciate the gentleman's questions. The chair now recognizes the gentleman from Oklahoma for five minutes.
C
Congressman from Oklahoma2:11:25
Thank you, Mr. Chairman. Mr. Smith, what is your current job?
R
Richard Smith2:11:33
I'm retired.
C
Congressman from Oklahoma2:11:35
You're retiring? Are you still getting paid by the company?
R
Richard Smith2:11:38
No, sir.
C
Congressman from Oklahoma2:11:40
Oh, you're fully retired, and so you have no affiliation at all with the company? Not as a contractor or anything?
R
Richard Smith2:11:47
Congressman, I agreed to do — because I love this company, I spent 12 years with 10,000 people trying to do the right thing — I told the board it was right for me to step down, to have new leadership take this company in a new direction. So when I retired, I agreed to work for as long as the board required for free, to help make it right for the consumers. So the affiliation is through doing free work with the board of directors and the interim CEO.
C
Congressman from Oklahoma2:12:18
So you're not getting paid in any manner? Not any type of shares, no stocks, anything?
R
Richard Smith2:12:22
Nothing. The day I announced my retirement —
C
Congressman from Oklahoma2:12:28
You still own stock in the company? I'm sorry, do you still have stock in the company?
R
Richard Smith2:12:31
Oh, yes.
C
Congressman from Oklahoma2:12:33
Have you sold any of it?
R
Richard Smith2:12:35
I've been here for 12 years. Yes, sir.
C
Congressman from Oklahoma2:12:37
In recent, since this became aware to the public during this breach?
R
Richard Smith2:12:43
No, sir.
C
Congressman from Oklahoma2:12:45
Are you aware of the individuals that have —
R
Richard Smith2:12:48
Yes, there are three individuals who reported directly to me while I was there as CEO that sold stock. Yes.
C
Congressman from Oklahoma2:12:55
And they're all three of them —
R
Richard Smith2:12:57
Men I've known — I mentioned earlier, for a number of years, two for almost 12 years and one for three or four years — and they're men of high integrity.
C
Congressman from Oklahoma2:13:05
Did they sell it before this went public?
R
Richard Smith2:13:09
Yes. As I said before, the knowledge — we went public with this on September 7th. And when did they sell their stock? August 1st and 2nd. So after the breach —
C
Congressman from Oklahoma2:13:21
No, the timeline —
R
Richard Smith2:13:25
The end of July, 29th and 30th, the notification of the 31st of suspicious activity. At that time, one to two days prior to their selling, there was no indication. So what would cause them to sell it? There is, as a Section 16 officer, a limited window in which they can sell. It tends to be right after the earnings call, for no more than 30 days. So this is a natural process. The window opened after the second quarter window.
C
Congressman from Oklahoma2:14:02
In your opening statement, you made mention that there was an error in the portal, and it was three weeks before you were notified of a breach.
R
Richard Smith2:14:11
If I may clarify, yes. There was a software — it's called an open source software — that was deployed in this environment, this consumer dispute portal. We never found that vulnerability, didn't patch the vulnerability. That was the issue.
C
Congressman from Oklahoma2:14:31
So who was in charge overseeing that? Who was supposed to be watching those portals for you?
R
Richard Smith2:14:36
Ultimately me. I know ultimately me, I get that. But who did you have hired that was supposed to watch that? There was, on the vulnerability side, you have a department that's dedicated to this. There's the chief investment officer — or chief information officer — was ultimately responsible.
C
Congressman from Oklahoma2:14:54
Is that person still over that department?
R
Richard Smith2:14:59
No, sir. He's gone.
C
Congressman from Oklahoma2:15:02
You said you put in, once you were made aware of the breach, you put in four plans of action, right? The first one was — you remember?
R
Richard Smith2:15:17
Notification, notification. Second one was a call center. Third one was increase cyber attacks, preparing for that. Fourth one was coordinating with law enforcement. I'm also, or was, CEO of a company not the size that you have, but from the companies that my wife and I have had, we have protocols put in place of what could happen. We know cyber attacks happen, you hear it every day on the news.
C
Congressman2:15:50
These four things that you named were common sense things that should have been put in place to begin with. It should have been a fire alarm. You're in that world. This should be on the side of the wall where you pull the handle and it immediately goes into place. How was it that it was just now thought of that you need to have four common sense principles put in place on how to react to something in a world where we knew you were vulnerable? We have protocol, the team follow protocol. This is well known what to do from hiring a cyber forensic expert. We knew what to do. We've done it before. It's engaging a world-leading cyber arm of a law firm. We knew what to do. These are all protocols that they knew what to do. The one thing, Congressman, that's not a switch on a wall has the ability to stand up the environment we had to stand up. It took a long time to stand up, and that's the issue that we have here. You are on the leading front of this, and the four things that you identified to me, I don't mean to simplify it by saying a switch on the wall, but these protocols should already been put in place, and you should have been able to react much, much sooner than what took place. And with that, I'm sorry, I don't mean to cut you off, but the chairman has indulged me longer than what he should have, and I appreciate your time. Thank you, thank you very much.
C
Chairman2:17:14
Gentleman, time has expired. The chair now recognizes the gentlelady from California, Mrs. Waters, for five minutes.
M
Maxine Waters2:17:21
Thank you, Mr. Chairman. Mr. Smith, before I get to my question, I just want to say that on behalf of the 15 million Californians whose information was exposed, we expect better. Your business model was based on collecting and maintaining the most sensitive information on folks, and you let us all down, and that happened on your watch. And from my briefings, it appears that this could have been and frankly should have been prevented. Now, Equifax's business model depends on gathering consumer information, repackaging it, and selling it. Equifax has set up a website in which consumers can enter information to determine if they are at risk and sign up for credit monitoring and credit lock. To participate, a person has to give Equifax the same type of personal information, including social security number, which Equifax put at risk in this breach. I want to know what Equifax is planning to do with this information besides offering credit monitoring and credit locks. Can you ensure me that Equifax will not plug this information back into its core business operation and sell it to its lenders? Equifax should not benefit from this situation, and I want to know that Equifax is going to wall off this information and guarantee that the company will not profit from this situation.
R
Richard Smith2:18:40
Congresswoman, thank you for your comments. And as I mentioned in my written testimony, my oral testimony, and I've said throughout the morning, I'll say again today, as a CEO, it was under my watch. I'm responsible, I'm accountable, and I apologize to all your consumers in California. The intent of this offering that we're giving to your constituents in California and consumers across the country is an environment where we're not going to sell other products. They need to come there and be serviced with protection of the five offerings that you had mentioned, not to sell and take your data and monetize that. It's to take and protect you with these five services.
M
Maxine Waters2:19:23
Okay. Equifax's breach notification website uses a stock installation of WordPress. This causes me a lot of concern because it seems to have insufficient security for a site asking people to provide part of their social security number. Can you assure me that this website is secure and will not further endanger the personal information of my constituents?
R
Richard Smith2:19:47
Congresswoman, we took what we believe was the right amount of time working hastily from late August to going live on the 7th. One of the four work streams the congressman from Oklahoma mentioned was ensuring we were prepared for what was going to be increased cyber attacks, as told to us by our forensic examiners. And one of the first things we did was ensure that the website that we're bringing consumers to to get these free services was as secure as possible, so that was one of our top priorities.
M
Maxine Waters2:20:19
Okay. And finally, my last question is, how many U.S. consumers have enrolled in the credit monitoring training service TrustedID? I'll just finish here because I know multiple people who have enrolled, including my immediate family, and they were told that they would receive an email to complete the process. After days of waiting, they have not received an email and wanted to know what the delay in processing this protection and when will they be able to complete the process to help protect their information.
R
Richard Smith2:20:48
I understand the question. I mentioned earlier that over 400 million consumers have come to the website. Obviously, we don't have 400 million consumers in our country, so a number of them came back multiple times, but it's a lot of volume. Number two, I was told in the last few days that the backlog waiting for those emails has now been fulfilled, has been drained. As you come into the system, it's a more immediate response, so the team seems to have made great progress in the last couple weeks.
M
Maxine Waters2:21:15
Okay, thank you. And I yield back the balance of my time.
C
Chairman2:21:18
Thank you, thank you very much. The gentlelady yields it back, and the chair now recognizes the gentleman from Pennsylvania for five minutes.
C
Congressman (Pennsylvania)2:21:26
Thank you, Mr. Chairman. I've heard from hundreds of constituents in my congressional district. There are approximately five and a half million in Pennsylvania. I've reviewed each and every one of the constituent stories that I've received, and amongst my growing concerns: your baseline security practices leading up to the breach, the company's awareness of the breach developments and relevant timing, how consumers can get assistance in securing their accounts, how reliable the recovery efforts are in the wake of the breach, and the path forward long term for consumers' personal information and making sure they are safe. Despite the breach, it's this last one that is so particularly angering because it is going to potentially be so destructive to hundreds of millions of Americans, what might happen to them in the years to come. And as the head of the company, and throughout the company, the culture of that company has to know how predictable the damage can potentially be. And so I ask you, is it not predictable how bad it might get for the individuals who have been compromised in terms of how much damage could be wrought upon them individually in the years to come?
R
Richard Smith2:23:52
Congressman, let me start by saying that, like you, I've talked to consumers across this country who've been impacted. I personally read letters from consumers complaining, voicing their anger and frustration, so I know what you're seeing back home in Pennsylvania. I think the anger is going to be multiplied thousands of times when something actually happens. And so when you talk about how predictable some of this is, the rollout of the call centers and the second rollout and the third rollout, it has to be predictable how massive this is and what would need to be put in place from a protocol perspective in order to address what's coming. And the slow rollout and how poor it was done to me is just inexcusable. I mean, you have to have departments dedicated to dealing with this potential, and it doesn't appear to me as though that was planned, or if it was planned, it was planned extremely poorly.
I understand your point, but it requires a little more color. We went from 500 call center agents to a need of almost 3,000 properly handled call center agents to handle consumer calls. It took time. We did the best we could in a short period of time. We ramped those up. I mentioned in my opening comments, two of our larger call centers in the first weekend were taken out by Hurricane Norma. We were not prepared for that kind of call volume.
C
Congressman (Pennsylvania)2:24:21
How couldn't you be? How couldn't you be? It's not a traditional business model. We are traditional business models dealing with cut companies, not 400 million consumers. But your business model has a couple hundred million customers, so on a breach of this scale, obviously you're going to have at least that number and probably twice that amount of people calling inquiring as to whether or not they're subject to the breach, and that wasn't done.
R
Richard Smith2:24:51
Congressman, the difference is again the primary business model we have is dealing with companies, not with hundreds of millions of consumers. We did the best we could to react as quickly as we could. I'd mentioned that the service is getting better each and every day. We've listened to consumers' feedback, tried to make changes to the website URL, any changes to the call center.
C
Congressman (Pennsylvania)2:25:11
You're familiar with the Safeguards Rule, that's essentially what you operate under, yes? How often does a forensic consultant issue a letter or a certification, or a law firm issue a certification that they feel your protocol is in compliance with the Safeguards Rule?
R
Richard Smith2:25:28
We are in compliance. I'm not sure how often that is actually communicated as you're saying.
C
Congressman (Pennsylvania)2:25:31
How would you know that you're in compliance then? Because if you said you filed protocol and protocol led to this, then it's very difficult for me. I mean, that calls into question whether the Safeguards Rule is sufficient enough, because if you're saying that you're in compliance with it and you follow protocol and this still happened, that unearths a whole other set of questions.
R
Richard Smith2:25:53
Again, the speed of a reaction and the scale of the reaction was unprecedented. I'm not taking excuses.
C
Congressman (Pennsylvania)2:25:59
But there's a corporate governance issue here as I see it. And that is, your board of directors gets together, your CEO, you have a Chief Information Officer, you have a Chief Security Officer, and at least once a year and probably quarterly, you have, I presume, outside forensic consultants doing this stuff every single day from you on retainer. And the speed at which you have to do this just to run your company operationally, you don't ever stop it. It's obviously ongoing and persistent. And it just seems to me that through insurance policies, through reporting to your board, through your board wanting to make sure that they're doing their job, you're going to be looking for certifications from your outside security forensic consultants doing audits to say, 'Yep, you're doing good, you're doing good. Here are the new threats, here's how we're updating.' And I just don't see that's the kind of information I think would be extremely helpful that we have not received any information from today. But I would ask you, since I'm well over my time, that I'd like to know how often your board asks you to certify whether or not you're in compliance, and what is that protocol, and how, when was the last time you updated that protocol? You said you've complied with protocol. When was the last time that was updated?
R
Richard Smith2:27:12
I understand your question. We'll get to the information.
C
Congressman (Pennsylvania)2:27:14
Do you yield back? After you're already well over... I yield back. Time is expired. How's that?
C
Chairman2:27:20
The chair now recognizes the gentleman from New York for five minutes.
C
Congressman (New York)2:27:34
Thank you, Mr. Chair. Americans should know their sensitive personal information is safe. Their security is exposed when private companies, including Equifax, can collect their private information without their direct knowledge or consent. And it's why I'm cosponsoring Representative Schakowsky's measured H.R. 3896, the Secure and Protect Americans' Data Act. Mr. Smith, we are here today because months after the breach actually took place, your company Equifax revealed that its for-profit business practices have exposed the highly sensitive personal information of some 145 and a half million Americans and counting. Your data breach exposed a critical vulnerability in the American economy and the information security of the American people. Victims of this breach span every age group, every race, class, and other demographic. They now face a lifetime at risk of fraud, identity theft, and other crimes as a result of the private data that you exposed. I have many, many questions, but allow me to be the conduit through which my constituents ask you, Mr. Smith, their questions. I'll go first to Garance, a constituent pointed out to me it would be wrong to call the victims of this breach Equifax customers. Most of them never asked to be tracked and judged by a private company with little public oversight or accountability. This is unacceptable, and he asks why he's been impacted in this manner. Any comment to Mr. Garance's question?
R
Richard Smith2:29:10
Again, Congressman, I have read many similar letters and talked to people back home in Atlanta who voiced that same concern. I can tell you this: our company has been around for 118 years. You have 10,000 employees trying to do what's right each and every day. I apologize to the individual who wrote you that letter. I apologize to America for what happened, and we're going to try to make it right.
C
Congressman (New York)2:29:39
Constituent Jason from Albany asked, 'Mr. Smith, did you, to the best of your knowledge, employ the best and most effective defense available to you to prevent this breach?'
R
Richard Smith2:29:50
You know, a crisis that never occurs if everything's gone right. In this case, as I mentioned earlier, we had a human error and a technology error. It wasn't because we were unwilling or unable to make the financial investments in people, process, or technology.
C
Congressman (New York)2:30:08
My constituent Tanya asks, 'How do I get Equifax to fix this without signing over my rights, and what related costs will I, Tanya, be expected to pay over my lifetime?'
R
Richard Smith2:30:20
The five products we launched are the services we offered in September. They are all free. They're all spelled out in a press release. They give that individual significant protection. The most comprehensive change is coming in January of next year, which is the ability for consumers to lock and unlock their data when they want and only when they want. And any related costs that she should expect to pay, those services are all free.
C
Congressman (New York)2:30:46
A number of my constituents would like to know, given that the sole purpose of credit agencies is to secure handling of consumers' confidential information, which they spectacularly failed to do, why is this company allowed to continue to exist?
R
Richard Smith2:31:01
We have a rich history of helping those who want to get access to credit. The company has done many great things to help those in the unbanked world who would never otherwise have access to credit, because what we do brings them into the credit world.
C
Congressman (New York)2:31:20
Stitch Went Lee from Albany asks, 'Why are you using this gross misconduct to turn your victims into customers for a paid monitoring service that you will profit from?'
R
Richard Smith2:31:29
That is not the intent. Our intent is to offer those five services for free, followed by the sixth service, which is a lifetime lock for free.
C
Congressman (New York)2:31:39
Constituent Karen asks, 'Why have you not notified each person whose data you compromised? Most never asked you to collect it and securely store their private information. You are the representatives, and why should they be responsible for your malpractice?'
R
Richard Smith2:31:57
Following the recommendation of those who advised us, we did notify through the press release, notifying the entire population, not just those who were a victim of the criminal act, but all Americans to get access to these products and services for free.
C
Congressman (New York)2:32:16
And my constituent James from Defritsville, New York asks, 'Why did it take you so long to announce the data breach, and why shouldn't you be held responsible for every day of failing to report?'
R
Richard Smith2:32:28
I think hopefully my written testimony, my oral testimony, the dialogue we've had today has talked about the timeline with enough granularity to help that person understand what occurred from March through September 7th.
C
Congressman (New York)2:32:44
And a constituent Stephanie from East Greenbush asked, 'Do they know if the people were targeted or randomly picked? Why some but not others?'
R
Richard Smith2:32:55
At this point, all indication is it was at random. It was not targeting individuals specifically.
C
Congressman (New York)2:33:01
I've exhausted my time, but let me assure you, Mr. Smith, I have many, many, many constituent questions that continue to pour forth, and we're going to provide those after the hearing here and would expect that they would all be answered. And again, thank you for your response. Thank you. I yield back, Mr. Chair.
C
Chairman2:33:22
Thank you very much. The gentleman yields back. The chair now recognizes the gentleman from Pennsylvania for five minutes.
C
Congressman (Pennsylvania, second)2:33:29
Thank you, Mr. Chairman, for allowing me to sit on this hearing. My fellow members have already asked a lot of questions, very important high-level questions, but I want to take a few moments to dig a little more deeply into a few specific issues. We now know that Equifax's information security department ran scans that should have detected systems that were exploitable by the Struts vulnerability, but that the scans didn't detect any. Obviously, at least one system was vulnerable. So if the scan was improperly configured to catch this vulnerability, in other words, you missed a major breach, is it possible that it has also been improperly configured to detect similar vulnerabilities?
R
Richard Smith2:34:10
I have no knowledge of that. I have no knowledge that being the case.
C
Congressman (Pennsylvania, second)2:34:14
But now you have to feed the information. These scans have to be complete and accurate information, and this information apparently wasn't fed in, or was fed in an incomplete way. Isn't that true?
R
Richard Smith2:34:27
Can you repeat the question, please?
C
Congressman (Pennsylvania, second)2:34:29
In order to scan something, you have to feed, a human has to feed it information, right?
R
Richard Smith2:34:34
I'm not a scanning expert, Congressman. My understanding is you've got to configure the scanner in certain ways, look for certain volume, but a lot of what's going on here is you're blaming... They say no humans are involved here, but configuring is done by a human being, isn't it right? And some inaccurate information got in there too.
C
Congressman (Pennsylvania, second)2:34:44
So if it was improperly configured to catch the vulnerability, is it possible it has also been improperly configured to detect similar vulnerabilities?
R
Richard Smith2:34:59
I have no indication to believe that's the case.
C
Congressman (Pennsylvania, second)2:35:03
We've also heard a lot about the website Equifax set up to handle the consumer protection response at EquifaxSecurity2017.com. As it's been pointed out, this looks like a website that scammers would use for phishing. In fact, it's widely reported in the press that someone switched two words and made it into a phishing website that looked almost identical. Luckily, this person was just trying to make a point, but I think that point's well taken. You said earlier today that you set up this external website because Equifax's own domain wouldn't be able to handle the sheer amount of traffic. Now, why wouldn't your website be able to handle this traffic? I mean, it just doesn't make sense. A company of your size and knowledge doesn't understand how to handle traffic for over 100 million people? Don't you use an elastic cloud computing service that would have accounted for this traffic?
R
Richard Smith2:35:41
Congressman, a point of clarification. If I made it sound like the phishing site that you referred to, which was mentioned a few times today, was an error by an individual in the call center.
C
Congressman (Pennsylvania, second)2:35:56
Well, let me get another question, though. I just want to ask about this question. Your own domain wouldn't be able to handle the sheer amount of traffic, but don't you use something like an elastic cloud that would allow for greater traffic?
R
Richard Smith2:36:09
The environment the microsite is in is a cloud environment. It's very, very scalable. The traditional environment that we operate in could not handle 400 million consumer visits in three weeks.
C
Congressman (Pennsylvania, second)2:36:23
Well, I'm going to come back to some of this stuff too. I want to come back to the issue of patching the March vulnerability. Now, I know this has come up a few times, but I want to make sure to highlight this point since it's critical in understanding how this breach occurred. Here, our understanding is that fixing this vulnerability required more effort than simply installing a patch, but we also understand that when Equifax did patch the vulnerability, it took less than three days to do so. So the patch only took a few days to apply. Why did Equifax fail to install it immediately after it was announced? This is critical.
R
Richard Smith2:36:50
Critical patching takes a variety of time. I'm not sure where you got the note that it's three days. Apache can take from days to up to a week or more to apply the proper patch.
C
Congressman (Pennsylvania, second)2:37:01
Did you notify everybody it was going to take some time? I'm sorry, did you notify all your customers it was going to take some time? Would you notify people there was the risk while you're trying to apply the patch?
R
Richard Smith2:37:12
I know of no standard protocol that we've notified... Standard protocol, yes.
C
Congressman (Pennsylvania, second)2:37:15
Did you notify people?
R
Richard Smith2:37:18
I have no knowledge that we notify customers or consumers of a patching process.
C
Congressman (Pennsylvania, second)2:37:21
So you didn't notify anybody that the patch was going to take place. In the meantime, there was a risk that existed. Executives of your company, were you aware of it?
R
Richard Smith2:37:32
As I've said before, I was not.
C
Congressman (Pennsylvania, second)2:37:35
You were not aware that there was a problem with vulnerability? You said you just told me it takes a few days, a few weeks, but you weren't aware that it existed?
R
Richard Smith2:37:41
That's correct.
C
Congressman (Pennsylvania, second)2:37:43
Well, let me wrap up with one final thought here. In your testimony, you state that the breach occurred because of both human error and technological failures, or technology failures. So look at the three issues I just highlighted: the improperly configured scans, the poorly chosen website, the lack of patching. These are not failures of technology. A human misconfigured a scan, a human selected the website name, a human failed to apply the patch. Well, I understand that cybersecurity is an immensely complicated field. We've dealt with this many times as a committee, and sometimes flaws in the technology we rely on are really to blame. But I also think it's important to be upfront about the cause of breaches like this. If we continue to blame technology for human failures to provide inadequate cybersecurity, I think we're going to have a very difficult time improving our capabilities and preventing future cyber threats. Chairman, I recognize I'm out of time. We'll see you again in my subcommittee.
C
Chairman2:38:27
Thank you very much. The gentleman's time has expired, and the chair now recognizes the gentleman from Maryland for five minutes.
C
Congressman (Maryland)2:38:40
Thank you, Mr. Chairman. Mr. Smith, thank you for being here. You have been the president of the company, CEO for 12 years, is that right?
R
Richard Smith2:38:49
That is correct.
C
Congressman (Maryland)2:38:51
There are three things I think that the public is angry about. Certainly, as my colleague was indicating, we're getting a lot of messages and contacts, inquiries from our constituents across the country. First of all, they want to understand, and you've tried to explain it today, but I'm not sure it's going to be satisfactory, why there wasn't sufficient protections in place on the front end so that this kind of breach wouldn't happen in the first place, given the sensitivity of the information that you're keeping in the company. The second thing is how quickly, once a breach was discovered, you came clean to the public and provided information on what was happening. There seems to have been a delay there that concerns people. The third is whether the services that you're now providing to people, you've enumerated the five or six free services that you're providing to people, whether that's going to be a sufficient assurance to folks going forward that their identity can be protected, that their information is safe, and so forth. So you're trying to fix things now, but there's going to continue to be, I think, serious questions about all three of those things that I just mentioned. I wanted to ask you about the kind of remedies that you have out there, because there's some confusion. I got a question from a constituent who had purchased a monitoring service that would cover his family, including a child under the age of 18. So, first of all, can you tell me, is it possible for someone under the age of 18 to have their identity stolen?
R
Richard Smith2:40:50
Exactly correct.
C
Congressman (Maryland)2:40:52
As far as you understand?
R
Richard Smith2:40:55
Is it possible? Yes. As it relates to this breach, just generally, identity... If certain information about a minor is divulged to an unscrupulous actor, that can be used to steal the identity. If someone has a social security number at any age, can that be compromised? Yes. It could not be compromised in this case because this database they got into, my understanding, only was for those who had credit, or credit active or inactive, and they've been in a credit environment.
C
Congressman (Maryland)2:41:28
Okay, but my understanding is that when you provide a family service, you're collecting information and holding information that includes the social security number of people who may be under the age of 18.
R
Richard Smith2:41:47
I have no knowledge that under 18 not credit active was compromised here. I can look into that. I have no knowledge if that is the case.
C
Congressman (Maryland)2:41:59
Is this free service that you are providing going to cover any exposure or information that's related to a minor as opposed to somebody who's over the age of 18? If you had information on that minor...
R
Richard Smith2:42:15
I could look into that, Congressman. The intent of the coverage was to cover anyone in America who is in the credit system.
C
Congressman (Maryland)2:42:25
So if you're under 18 and not in the credit system, I'll check your one point, which is on this concept called family plan that you're alluding to, where you can lock down consumers, you monitor consumers. I don't believe their social security numbers were in this system. Well, we can verify that. Well, that's important because, just to interrupt, I think we had a little clock issue. We've had about 30 seconds left. I think it's important because it may be that with respect to credit reporting, the implications of this breach only attached to people that are 18 or older. But if you're holding information about minors, like a social security number, that's part of the portfolio of information you're getting from a family, for example, particularly when the family has paid for this service, you're holding their social security number. So any breach that makes that information available outside of the arena in which it's supposed to be kept close creates vulnerability for that person. It's not like we get a new social security number when we turn 18. So that's going to follow them all the way through and create some real risk for them. So I think that's a piece of this that we need to understand much better, and I want to thank my constituents for sort of bringing that to our attention.
R
Richard Smith2:43:48
I understand your point. To the best of my knowledge, that data is not included in the breach. I'll look into it. Thank you.
C
Chairman2:43:54
Thank you very much. The chair now recognizes the gentleman from Georgia for five minutes.
C
Congressman (Georgia)2:43:58
Thank you, Mr. Chairman. And I want to thank you for allowing me to sit in on this today. Mr. Smith, thank you for being here. I know it's been a tough day, it's been a tough past couple of weeks. I appreciate you being here, and that's important. I'm not going to apologize for my colleagues and their questions and their aggressiveness, if you will, because as you know, people are upset and they're mad. You get it, and I get it. We all understand it. But nor am I going to pile on, so I want to kind of go a different route, if you will. One of the things that I've learned in two and a half years that I've been up here is to be very careful about my Southern phrases, but one of my Southern phrases has always been that you know, fool me once, shame on you; fool me twice, shame on me. And I want to know what we can learn from this. Now, this is not the first time that a data breach has happened. Perhaps it's the biggest it's ever happened, but it's happened to other companies before. Now, to the extent that you weren't prepared for this or that it happened to you, and I hope that was not due to complacency, I hope it was not due to you not doing everything that you could to have prevented it. But my question is this: can you share with us any information about the attackers? What do you know and what do you not know about them at this point?
R
Richard Smith2:45:14
Congressman, thank you for that. As I mentioned in my opening comments and in my written testimony earlier this week, we've engaged the FBI, and they currently have the investigation in their hands. So at this juncture, we're not disclosing what we know about the hackers.
C
Congressman (Georgia)2:45:30
How's your cooperation with the FBI been? Is it your experience with them thus far been good? And anything that... This is important. It's important for everyone. Yeah, everyone's upset and rightfully so. They should be upset when your personal data is out there. It obviously is very upsetting. But I'm trying to go in a different direction. I'm trying to figure out how we can prevent this from happening.
R
Richard Smith2:45:59
The cooperation with the FBI, to the best of my knowledge, has been good. It's ongoing. We've got lines of communication into the FBI not just after a breach but routinely throughout the year. So I'd say it's been a very good cooperation.
C
Congressman (Georgia)2:46:12
Congressman, let me ask you this. Through this scenario, through this experience rather, if you had to do anything different, what would you have done?
R
Richard Smith2:46:21
Congressman, I was asked that question earlier, and my answer will be the same now as it was earlier. There'll be time for reflection personally and as an organization, that coupled with the investigation we continue to undertake to look at processes in-house. But at this juncture, since I was notified in mid-August through this morning, it's all been about the forensics. It's been about trying to protect and do what's right for the consumer, and there's been no time to reflect on what I'd do differently.
C
Congressman (Georgia)2:46:54
That's okay. Well, when that time comes, we need to know, because we don't need to let this happen again, and other companies need to learn from it. You know, this is obviously, as I said earlier, not the first. You're not the first company to suffer from this. You're not the first Georgia company to suffer from this. We understand that doesn't make it any less egregious to what has happened, but where I'm trying to go is what can we do better to prevent this from happening again? These guys are good, we know that. Listen, cybersecurity is hard. It's way above my pay grade, I can tell you that.
R
Richard Smith2:47:30
Congressman, thank you for that. As I mentioned in my comments, I take full responsibility as CEO, and I understand that. And I appreciate that. If there's one thing I'd love to see this country think about, it is the concept of a social security number in this environment being private and secure. I think it's time as a country to think beyond that. What is a better way to identify consumers in our country in a very secure way? I think that requires something different than an SSN, a date of birth, and a name.
C
Congressman (Georgia)2:48:10
Well, you're exactly right. I remember my time in the Georgia state legislature when we changed the driver's license number. It used to be your social security number, and we changed that. And that was not that long ago. And that's what tells me that this is something that is changing dramatically and quickly, and we need to be prepared for it. So I know that you're putting out fires right now, but at some point we need to learn from this. We need to know, look, we shouldn't have done this, we should have done that. What could we have done differently? What will benefit another company to allow that this doesn't happen? And I hope, and thus far you appear to have been honest about all this, I hope that if part of what the problem was was complacency, that you admit that and say don't ever let your guard down.
R
Richard Smith2:49:05
Thank you, Congressman. I would love to be part of that dialogue about what lies ahead to protect individuals' identities.
C
Congressman (Georgia)2:49:11
Well, again, I want to thank you for being here, and it says a lot about you and about your company. Thank you.
C
Chairman2:49:17
Thank you, Mr. Chairman. The gentleman yields back. The chair now recognizes the gentlelady from California for five minutes.
C
Congresswoman (California)2:49:25
Chairman, first I'd like to recognize former colleague that's here in the chamber with us, Saxby Chambliss, who served in the House and in the Senate. It's good to see you. Very nice to see you. Mr. Smith, it seems to me that you've accomplished something that no one else has been able to accomplish, and that is that you have brought Republicans and Democrats together in outrage and distress and frustration over what's happened, because this is huge. This is almost half of the country and their information. You know, the American people, I think they have privacy in their DNA. We don't like big brother. We don't like people having information on us. We know in an information and in a digital age that that's impossible, but boy, when that's breached, when the privacy goes out the window, it really puts a dent in people's lives. I equate it with, because they don't feel that they can do anything about it, they feel helpless. I come from earthquake country, and when that rattle first starts, you really do feel helpless. You feel absolutely helpless. Now, it's been the question has kind of been posed rhetorically by some members, because I've been sitting in for a while at this hearing, what can be done? I have the privilege of representing most of Silicon Valley. I have asked this question about the protection in terms of privacy breaches in our country to just about every CEO I've met, and they have responded like a chorus and said that there are two main reasons for breaches in our country. Number one, a lack of hygiene in systems and very poor security management. That's why I have legislation. Senator Hatch is the lead sponsor in the Senate. I have the bill in the House. So it's distressing to me, knowing this information, that Homeland Security notified Equifax. This is almost seven months ago. This has to do with a patch. So I know there are a lot of questions that have probed this, but you as CEO, at the time when Homeland Security informed your company that there was a breach, what did you say to your CIO? Did you understand what the breach was? Did you understand what the patch meant? Did you understand the timeliness, the need for timeliness to have this fixed? And did anything change in that department? Was there a new policy put in place by you?
R
Richard Smith2:53:00
I think, Congresswoman, to clarify, when the CERT came out in March, there was no notification of a breach. It was a notification of a vulnerability. What it meant was an open source software commonly used and deployed around the world called Apache Struts had a vulnerability, and the notification was that the vulnerability should be patched.
C
Congresswoman (California)2:53:38
All right. And did you ask if it was patched?
R
Richard Smith2:53:41
We get notifications. No, you got the notification from Homeland Security. All right, what did you do about it the day you found out?
The company was notified on, I believe, the 9th of March. The team, security team, followed protocol and instantly within a day sent notification out to many people in the organization that a patch needed to be applied to Apache Struts.
C
Congresswoman (California)2:54:06
And did you ask your team when it was applied?
R
Richard Smith2:54:12
The security team did, and they spoke with the IT team as well.
C
Congresswoman (California)2:54:17
When did they take care of it?
R
Richard Smith2:54:23
Throughout the testimony, we've talked about what occurred.
C
Congresswoman (California)2:54:27
Just tell me when it happened. When was it actually?
R
Richard Smith2:54:30
The following day, communication was sent out to those who need to be notified.
C
Congresswoman (California)2:54:33
You already said that. I want to know when they did it, when they took care of it.
R
Richard Smith2:54:41
They took care of it in July because we never found it. It wasn't until... You recall, we did the human error, we did the scan, the technology never found it. In July, he saw suspicious activity, took the portal down, found the vulnerability, applied the patch.
C
Congresswoman (California)2:55:00
Well, I thank the chairman. We have a... In the rules of the full committee, which are approved at the beginning of every Congress, that members of the full committee can participate in subcommittees where they are not members, and I appreciate the legislative courtesy. And I think that there's a lot more to be done on this issue. Mr. Chairman, if I might make the recommendation, I think we should have the CIO, the Chief Information Officer, come in, because I don't think that this is resolved. So thank you, thank you very much.
C
Chairman2:55:37
Time has expired, and we're just going to ask one quick follow-up questions. I'm going to yield to the ranking member first.
F
Frank Pallone2:55:48
Well, first of all, Mr. Chairman, I would like to insert for the record a letter from consumer groups, a letter from Credit Union National Association, and an article from WGN TV. Without objection, so ordered. Sorry. So in closing, Mr. Smith, I want to quote again from you from your testimony. You mentioned the five fixes, so-called, and you put this, 'This puts the control of consumers' credit information where it belongs, with the consumer.' So I want to ask you a question. What if I want to opt out of Equifax? I don't want you to have my information anymore. I want to be in control of my information. I never opted in. I never said it was okay to have all my information, and now I want out. I want to lock out Equifax. Can I do that?
R
Richard Smith2:56:51
Congresswoman, that requires a much broader discussion around the role of the credit reporting agencies, because that data, as you know today, doesn't come from the consumer. It comes from the furnishers, and the furnishers provide that data to the entire industry.
F
Frank Pallone2:57:09
You know, I understand that, and that's exactly where we need to go to a much larger discussion, because most Americans really don't know how much information, what it is that you have, and they never said okay. So I'm hoping this will lead to a wider discussion. Thank you.
C
Chairman2:57:29
Thank you very much. The gentleman yields back. And if I may just go back to what we added a little discussion earlier, but again going back to your testimony, from August 15th when you were informed that it appeared likely that consumer information had been stolen, again, why was there again a 10-day delay between finding out about that personal information that could have likely been stolen to developing that remediation plan? That 10-day window, why did it take 10 days to start that review, that remediation?
R
Richard Smith2:58:05
Well, Congressman, there was continuous work going on around the clock from that time through yesterday, trying to develop the product, the communication plan, stand up websites, inform those who need to be informed. It wasn't like on a certain date something occurred. It was continual motion by many people for many, many weeks.
C
Chairman2:58:28
Let me ask a quick follow-up on that then. Because again, with that 10-day period of time, when was the appropriate time that it was really to start talking to the consumers? At that point in time, or again waiting until when you did in September? Because again, there was that lag time. Information could have been stolen on individuals.
R
Richard Smith2:58:46
Yeah, the whole goal was to make sure the data we had was as accurate and clear for the U.S. consumer as possible. Number two was to make sure, for the forensic cybersecurity specialists, that our environment was as secure as possible. The member said expect increased attacks. Number three was to stand up the call centers and the websites for hundreds of millions of consumers, and that just took time, as I alluded to earlier.
C
Chairman2:59:21
Well, thank you very much. And there are no other members present to ask questions. We want to thank you very much for testifying before the subcommittee today. And pursuant to committee rules, I remind members that they have 10 business days to submit additional questions for the record. I ask that the witness submit his response within 10 business days upon request of any questions submitted. Without objection, the subcommittee is adjourned.