Back
Richard Smith
Former Chairman & Chief Executive Officer, Equifax

Fmr. Equifax CEO: Breach happened on my watch

🎥 Oct 03, 2017 📺 Fox Business ⏱ 5m 👁 1565 views
Former Equifax CEO Richard Smith testifies on Capitol Hill over the company's data massive breach.
Watch on YouTube

About Richard Smith

Former Equifax CEO Richard Smith testified before Congress in 2017 and 2018 regarding a data breach that compromised personal information of over 145 million Americans. Smith stated that the criminal hack "happened on my watch" and said he took "full responsibility" for the incident. He apologized to affected consumers and attributed the breach to a combination of human error, including a failure to apply a software patch, and technological error involving a scanner that failed to detect the vulnerability. During questioning, Smith said that Equifax's general counsel and other executives who sold stock in early August 2017 did not know it was a breach at the time, describing the incident as "suspicious activity" with no indication that personally identifiable information had been compromised. Smith stated that upon his retirement he agreed to step down with no further compensation, no bonus, and no severance. In a separate hearing, Senator Elizabeth Warren questioned Smith about Equifax's profits, which Smith confirmed had increased by more than 80 percent since 2013 despite multiple data breaches. Smith also acknowledged that Equifax receives revenue from LifeLock, a credit monitoring service that saw increased enrollment after the breach.

Source: AI-verified profile updated from Richard Smith's recent appearances. Browse all interviews →

Transcript (4 segments)
R
Reporter0:00
Richard Smith, Equifax guy, has begun his statement. He's saying taking full responsibility. Let's listen to that.
R
Richard Smith0:07
For you Americans have a right to know how this happened. I've prepared to testify today about what I've learned and what I did about this incident in my role as CEO and chairman of the board, and also what I know about the incident as a result of being briefed by the company's investigation, which is ongoing. We know now that this criminal attack was made possible because a combination of human error and technological error. Human error involved a failure to apply a software patch to a dispute portal in March of 2017. Technological error involved a scanner which failed to detect that vulnerability on that particular portal. Both errors have since been addressed. On July 29th and July 30th, suspicious activity was detected and the team followed our security incident protocol. The team immediately shut down the portal and began our internal security investigation. On August 2nd, we hired top cybersecurity forensic and legal experts. At that time we notified the FBI. At that time, to be clear, we did not know the nature or the scope of the incident. It was not until late August that we concluded that we had experienced a major breach. Over the weeks leading up to September 7th, our team continued working around the clock to prepare. We took four steps to protect consumers.
Step number one: determining when and how to notify the public, relying on the advice of our experts that we needed to have a plan in place as soon as we announced. Step two: helping consumers by developing a website, staffing up massive call centers, and offering services free to every American. Step three: preparing for increased cyber attacks, which we were advised by the cybersecurity experts that we should expect. And finally, step four: continue to coordinate with the FBI and their criminal investigation of the hackers, and also to notify other federal and state agencies in the rollout of our remediation program. The mistakes we made, which again I deeply apologize. I regret the frustration that many Americans felt when our websites and call centers were overwhelmed in the early days. It's no excuse, but it certainly did not help that Hurricane Irma shut down two of our larger call centers in the first few days after the breach. Since then, however, the company has dramatically increased its capacity, and I can report to you today we've handled over 420 million consumer visits to our website in just over three weeks, and the wait times at the call centers have been substantially reduced.
At my direction, the company offered a broad package of services to all Americans. In addition, we developed a new service available on January 31st, 2018 that will give all consumers the power to control access to their credit data by allowing them to lock and unlock their credit files when they want. They can do that for free for life. Putting the power to control access to credit data in the hands of the American consumer is a step forward. I look forward to discussing this new tool with you during my testimony. As we've all painfully learned, data security is a national security problem. Putting the consumer in control of their credit data is a first step towards a long-term solution to the industry problem of identity theft. But no single company can solve a larger problem on its own. I believe we need a public-private partnership to evaluate how to best protect Americans' personal data going forward. I look forward to being a part of that dialogue. Chairman Walden, Ranking Member Pallone, Chairman Lana, Ranking Members Kowski and the honorable members of the subcommittee, thank you again for inviting me here today to speak to you. I will close by saying again how sorry I am for this breach. On a personal note, I want to thank the many hardworking and dedicated employees who worked with me so tirelessly over the past 12 years at Equifax. Equifax is a very good company with thousands of great people waking up every day trying to do what is right. I know they'll continue to work tirelessly as we have over the past two months to right the wrong. I'm looking forward to answering your questions. Thank you.