About Richard Smith
Former Equifax CEO Richard Smith testified before Congress in 2017 and 2018 regarding a data breach that compromised personal information of over 145 million Americans. Smith stated that the criminal hack "happened on my watch" and said he took "full responsibility" for the incident. He apologized to affected consumers and attributed the breach to a combination of human error, including a failure to apply a software patch, and technological error involving a scanner that failed to detect the vulnerability.
During questioning, Smith said that Equifax's general counsel and other executives who sold stock in early August 2017 did not know it was a breach at the time, describing the incident as "suspicious activity" with no indication that personally identifiable information had been compromised. Smith stated that upon his retirement he agreed to step down with no further compensation, no bonus, and no severance. In a separate hearing, Senator Elizabeth Warren questioned Smith about Equifax's profits, which Smith confirmed had increased by more than 80 percent since 2013 despite multiple data breaches. Smith also acknowledged that Equifax receives revenue from LifeLock, a credit monitoring service that saw increased enrollment after the breach.
Source: AI-verified profile updated from Richard Smith's recent appearances.
Browse all interviews →
Transcript (34 segments)
C
Congresswoman0:00
I wanted to ask some questions about John Kelly, the chief legal officer, who I understand is responsible for security at Equifax, or was at least at the time of the breach and its discovery. Is that right?
R
Richard Smith0:12
That is correct, Congresswoman. And Mr. Kelly in turn reports directly to you, the CEO, correct?
C
Congresswoman0:17
Correct. Okay, so we were told that Mr. Kelly was informed by the chief security officer the week of July 30th—we've just been talking about that—that a cybersecurity incident, you mentioned that, had occurred. Is that correct?
R
Richard Smith0:33
He was notified, is my understanding, on the 31st of July. There was suspicious activity in a particular environment called a web portal that was a dispute environment.
C
Congresswoman0:45
We were told that Mr. Kelly, this is our staff, was informed at the same time that the incident might have compromised personally identifiable information. Is that correct?
R
Richard Smith0:58
The only knowledge I have is he was notified on the 31st there was suspicious activity in a consumer dispute portal.
C
Congresswoman1:08
Well, we were told that Mr. Kelly then wrote a short memo to you regarding the incident. Is that correct?
R
Richard Smith1:14
Correct, Congresswoman. In his email, it said some suspicious activity around that.
C
Congresswoman1:24
At the same time, three Equifax executives sold over one million dollars of Equifax stock. That's on August 1st and August 2nd. And it's reported that Mr. Kelly was ultimately responsible for approving those sales. Is it true that Mr. Kelly or one of his direct reports would have been required to sign off on these stock sales?
R
Richard Smith1:51
Yes. Mr. Kelly, who's our general counsel, owns the clearance process. And he may—I have a lot of questions. So the answer is yes, he had to—he was supposed to sign off, yes.
C
Congresswoman2:05
Did any one of these three executives have knowledge the cybersecurity incident had occurred?
R
Richard Smith2:13
To the best of my knowledge, Congresswoman, no.
C
Congresswoman2:19
When were they informed that the incident had occurred?
R
Richard Smith2:23
I don't know exactly the date that they were informed, but they were not, best of my knowledge, they had no knowledge at the time they cleared their trades.
C
Congresswoman2:30
The general counsel, do you know for sure that they didn't know?
R
Richard Smith2:34
Best of my knowledge, they did not know.
C
Congresswoman2:38
And Mr. Kelly, who we were told knew of the breach and that it contained personal information, and yet still approved the stock sale, is he still chief legal officer for Equifax?
R
Richard Smith2:51
Congresswoman, I would come back to it again. He did not know it was a breach when he approved it. It could have been a breach. All he knew at the time, is my understanding, is suspicious activity when he approved the sales.
C
Congresswoman3:03
What the act is suspicious, it could be a breach, right?
R
Richard Smith3:07
It was deemed a suspicious activity. We had no indication that PII was in fact compromised at that time. We had no idea if data was exfiltrated at that time.
C
Congresswoman3:17
So now I understand that you agreed to forego your 2017 bonus, which has been about three million dollars for the past two years, correct?
R
Richard Smith3:27
That is correct.
C
Congresswoman3:30
But it's been reported that you will still retain 18 million dollars in pension benefits from Equifax. Is that accurate?
R
Richard Smith3:36
That is correct. Retiring, which is the category right now, although the company maintains the right to change that designation.
C
Congresswoman3:45
Also means you'll be free to sell your Equifax stock, which is worth about 24 million dollars. Is that correct?
R
Richard Smith3:52
Congressman, that calculation—it's hard to say. It's a complicated calculation. It depends on the total shareholder return of the company at the time the stocks vest. There's multiple variables. That may be an estimate. I've seen different estimates. It's hard to say what that number is. We won't know till the end of the year.
C
Congresswoman4:09
And that's in addition to Equifax stock you sold earlier this year for 19 million dollars. Is that correct?
R
Richard Smith4:15
That sounds correct.
C
Congresswoman4:20
And according to one report, you could be eligible for 22 million dollars in performance-based compensation depending how Equifax stock performs in the next three years. Is that right?
R
Richard Smith4:29
Let me be very clear, Congresswoman. When I announced my retirement and thought it was best for the company to move forward with a new leader, I agreed to step down at that time with no further compensation. I agreed I should not get a bonus. I agreed it would be no severance. I asked for nothing beyond what I'd already earned.
C
Congresswoman4:53
I was just informed by my staff that the chief security officer told the chief legal officer verbally that there was PII. That according to a call with staff yesterday, that actually there was a mention of the breach of personally identifiable information. The CSO told that.
R
Richard Smith5:23
Congresswoman, I have no documentation, no insight, no knowledge that anyone in the company had informed me, or in that case the chief security officer or the chief general counsel, that there was a breach on July 31st.
C
Congresswoman5:38
Is that what you said? Yes. No, we didn't say a date. I'm told that our staff didn't say a date. Okay, let me just say I'm glad the FBI is looking into it. Many state attorneys general, the city of Chicago has sued, so we'll probably get more information that way as well. Thank you.
C
CNBC Host5:59
Hey there, thanks for checking out CNBC on YouTube. Be sure to subscribe to stay up-to-date on all of the day's biggest stories. You can also click on any of the videos around me to watch the latest from CNBC. Thanks for watching.