Back
Richard Smith
Former Chairman & Chief Executive Officer, Equifax

Equifax CEO Richard Smith Testifies On Hacking That Compromised Millions Of Americans Personal Info

🎥 Oct 03, 2017 📺 Jon Selman ⏱ 6m 👁 13 views
Watch on YouTube

About Richard Smith

Former Equifax CEO Richard Smith testified before Congress in 2017 and 2018 regarding a data breach that compromised personal information of over 145 million Americans. Smith stated that the criminal hack "happened on my watch" and said he took "full responsibility" for the incident. He apologized to affected consumers and attributed the breach to a combination of human error, including a failure to apply a software patch, and technological error involving a scanner that failed to detect the vulnerability. During questioning, Smith said that Equifax's general counsel and other executives who sold stock in early August 2017 did not know it was a breach at the time, describing the incident as "suspicious activity" with no indication that personally identifiable information had been compromised. Smith stated that upon his retirement he agreed to step down with no further compensation, no bonus, and no severance. In a separate hearing, Senator Elizabeth Warren questioned Smith about Equifax's profits, which Smith confirmed had increased by more than 80 percent since 2013 despite multiple data breaches. Smith also acknowledged that Equifax receives revenue from LifeLock, a credit monitoring service that saw increased enrollment after the breach.

Source: AI-verified profile updated from Richard Smith's recent appearances. Browse all interviews →

Transcript (21 segments)
C
Chair0:00
Or information that way as well. Thank you, thank you very much. The gentlelady's time has expired. The chair now recognizes the chairman of the full committee, the gentleman from Oregon, for five minutes.
C
Congressman0:10
Thank you, Mr. Chairman. Mr. Smith, thanks again for being here today. You know, this is a sample of a copy of an Equifax credit report in my hand. It lists Social Security numbers, address, credit history, debts, all the sort of personal financial information. It's the lifeblood of Equifax, right? I mean, these data points are really, really important to what you do as a company.
R
Richard Smith0:35
Congressman, that's correct. It's a three billion dollar company, data on 820 million customers worldwide. And yet it appears this breach happened because the company didn't know it was running software and certain software on its system, right? The Apache Struts software that had the patch requirement. Congressman, as I alluded to in my opening comments and the recent written testimony, there was a human error and a technology error that did not allow us to identify, and I think that's what we're trying to get to here.
C
Congressman1:08
If I understand it right, your own information technology system did not tell the Equifax Security Division that the Apache Struts software, which contained the vulnerability that led to this breach, was running on the Equifax system. How did that happen, Congressman?
R
Richard Smith1:25
The day after the notification came out from CERT, the security team notified a wide range of people in the technology team who were responsible for them finding a patch, finding the vulnerability, applying the patch, and then days later, as is typical protocol, to deploy a technology scanner to then go look for the vulnerability, find the vulnerability. If it found a vulnerability, knew it was not patched. Both human deployment of the patch and the scanning deployment did not work. The protocol was followed.
C
Congressman2:08
OK, so then people asked us, how does that happen? If a sophisticated company like you headed is with so much at risk, how does this happen? And you know, we have colleagues that say we're going to double the fines, triple the fines, put fines in, do all these things. But how does this happen when so much is at stake? I don't think we can pass a law that, excuse me for saying this, but fix is stupid. I can't fix stupid, as a colleague of mine used to say. With so much at risk, I've talked to other software companies and people in this space who say some companies have an automated system that when a patch comes out, it automatically gets installed. That's not what you had, necessarily, right?
R
Richard Smith2:55
I'm unaware of an automatic automatic patch system. We have in place is security gets notification, and it's not uncommon to get notification from software providers routinely about vulnerabilities that are discovered. They followed the protocol, which is to notify the appropriate people within the time frame that the protocol called for. Unfortunately, the human error was they did not find the patch.
C
Congressman3:19
No, if I could, the human error, pshew, reference is that they didn't know that that particular software was running on your system. Apache Struts was running. That's what needed patching, right?
R
Richard Smith3:31
Congressman, great question. If I may clarify, please. Human error was individual who is responsible for communicating in the organization to apply the patch did not.
C
Congressman3:48
So does that mean that that individual knew that the software was there and it needed to be patched and did not communicate that to the team that does the patching? Is that the heart of the issue here?
R
Richard Smith4:01
That is my understanding, sir.
C
Congressman4:02
And there's no... Yeah, I was on a bank board for a while, and you know, we always had sort of double, double checks on everybody, right? Do you not have a double check of some sort, an audit of some sort? Is there? It seems like that was a single point.
R
Richard Smith4:20
The double check was the scanning device that was deployed a few days later.
C
Congressman4:25
But did the scanning device... I don't know how that process works. Does it know you have that software? Do you have to tell it that's what you're scanning for?
R
Richard Smith4:32
It's the latter. You got to tell it what it's looking for. It scans the environment. So that the individual who didn't tell the IT team, I'll call it the IT team, whatever the security team, that's where the individual failed.
C
Congressman4:43
Is it was that the same person telling them what to look for?
R
Richard Smith4:47
No, the scanner is deployed by the security team. And I should clarify there that the rationale, the reason why the scanner, the technology piece, did not locate the right vulnerability is still under investigation by outside counsel.
C
Congressman5:00
All right, one final question. You've referenced this suspicious movements of data. You've referenced incident. American people think all of that is breach. How regularly did you have incidents or suspicious movement of data? Is this a routine thing that people call, 'Hey, we had another incident, we got another suspicious movement of data,' or was this sort of outside normal, Congressman?
R
Richard Smith5:24
Thank you for the operations. As you alluded to in your comments, we do have a lot of data, and our primary goal is to protect that data. We have experienced millions of suspicious activity against our database any given year. But to the point that the head of your security team comes to you and says, 'Hey, we've got another one,' oh yeah, that that is not uncommon. It's not... How awful would that happen in the course of a week that they would come to the CEO and say, 'Heads up'? It's... Yeah, I don't have a number for you, Congressman, but it's not uncommon. It's not uncommon for us to engage forensic audit firms. It's not uncommon for us to engage outside counsel to help us think things through when there's suspicious activity. It's a part of doing business, innovative business, as you alluded to.
C
Congressman6:15
I thank you for the indulgence on the committee. I yield the balance of my time.
C
Chair6:18
The gentleman yields back, and the chair recognizes the ranking member of the full committee, the gentleman from New Jersey.