Retail Credit Company
   HOME

TheInfoList



OR:

Equifax Inc. is an American multinational consumer credit reporting agency headquartered in
Atlanta, Georgia Atlanta ( ) is the capital and most populous city of the U.S. state of Georgia. It is the seat of Fulton County, the most populous county in Georgia, but its territory falls in both Fulton and DeKalb counties. With a population of 498,715 ...
and is one of the three largest consumer credit reporting agencies, along with
Experian Experian is an American–Irish multinational data analytics and consumer credit reporting company. Experian collects and aggregates information on over 1 billion people and businesses including 235 million individual U.S. consumers and more t ...
and
TransUnion TransUnion is an American consumer credit reporting agency. TransUnion collects and aggregates information on over one billion individual consumers in over thirty countries including "200 million files profiling nearly every credit-active consum ...
(together known as the "Big Three"). Equifax collects and aggregates information on over 800 million individual consumers and more than 88 million businesses worldwide. In addition to credit and
demographic data Demography () is the statistical study of populations, especially human beings. Demographic analysis examines and measures the dimensions and dynamics of populations; it can cover whole societies or groups defined by criteria such as edu ...
and services to business, Equifax sells credit monitoring and
fraud prevention In law, fraud is intentional deception to secure unfair or unlawful gain, or to deprive a victim of a legal right. Fraud can violate civil law (e.g., a fraud victim may sue the fraud perpetrator to avoid the fraud or recover monetary compens ...
services directly to consumers. Equifax operates or has investments in 24 countries in the Americas,
Europe Europe is a large peninsula conventionally considered a continent in its own right because of its great physical size and the weight of its history and traditions. Europe is also considered a Continent#Subcontinents, subcontinent of Eurasia ...
, and
Asia Pacific Asia-Pacific (APAC) is the part of the world near the western Pacific Ocean. The Asia-Pacific region varies in area depending on context, but it generally includes East Asia, Russian Far East, South Asia, Southeast Asia, Australia and Pacific Isla ...
. With over 14,000 employees worldwide, Equifax has nearly US$5 billion in annual revenue and is traded on the
New York Stock Exchange The New York Stock Exchange (NYSE, nicknamed "The Big Board") is an American stock exchange in the Financial District of Lower Manhattan in New York City. It is by far the world's largest stock exchange by market capitalization of its listed c ...
(
NYSE The New York Stock Exchange (NYSE, nicknamed "The Big Board") is an American stock exchange in the Financial District, Manhattan, Financial District of Lower Manhattan in New York City. It is by far the List of stock exchanges, world's largest s ...
) under the symbol EFX.


History

Equifax was founded by Cator and Guy Woolford in
Atlanta, Georgia Atlanta ( ) is the capital and most populous city of the U.S. state of Georgia. It is the seat of Fulton County, the most populous county in Georgia, but its territory falls in both Fulton and DeKalb counties. With a population of 498,715 ...
, as Retail Credit Company in 1899. By 1920, the company had offices throughout the United States and Canada. By the 1960s, Retail Credit Company was one of the nation's largest credit bureaus, holding files on millions of American and Canadian citizens. Even though the company continued to do credit reporting, the majority of its business was making reports to
insurance Insurance is a means of protection from financial loss in which, in exchange for a fee, a party agrees to compensate another party in the event of a certain loss, damage, or injury. It is a form of risk management, primarily used to hedge ...
companies when people applied for new insurance policies, such as life, auto, fire and medical insurance. RCC also investigated insurance claims and made employment reports when people were seeking new jobs. Most of the credit work was then being done by a
subsidiary A subsidiary, subsidiary company or daughter company is a company owned or controlled by another company, which is called the parent company or holding company. Two or more subsidiaries that either belong to the same parent company or having a s ...
, Retailers Commercial Agency. Retail Credit Company's information holdings and willingness to sell its information attracted criticism in the 1960s and 1970s. These included that it collected "...facts, statistics, inaccuracies and rumors ... about virtually every phase of a person's life; his marital troubles, jobs, school history, childhood, sex life, and political activities." The company was also alleged to reward its employees for collecting derogatory information on consumers."Separating Equifax from fiction"
''Wired'', September 1995, retrieved September 13, 2007
In 1970, after the company had computerized its records, which led to wider availability of the personal information it held, the U.S. Congress held hearings that led to the enactment of the
Fair Credit Reporting Act The Fair Credit Reporting Act (FCRA), 15 U.S.C. § 1681 ''et seq'', is U.S. Federal Government legislation enacted to promote the accuracy, fairness, and privacy of consumer information contained in the files of consumer reporting agencies. It ...
. This legislation gave consumers rights regarding information stored about them in corporate databanks. It is alleged that the hearings prompted the Retail Credit Company to change its name to Equifax in 1975 to improve its image. Equifax expanded into commercial credit reports on companies in the United States,
Canada Canada is a country in North America. Its ten provinces and three territories extend from the Atlantic Ocean to the Pacific Ocean and northward into the Arctic Ocean, covering over , making it the world's second-largest country by tot ...
and the UK, where it came into competition with companies such as
Dun & Bradstreet The Dun & Bradstreet Corporation is an American company that provides commercial data, analytics, and insights for businesses. Headquartered in Jacksonville, Florida, the company offers a wide range of products and services for risk and financia ...
and
Experian Experian is an American–Irish multinational data analytics and consumer credit reporting company. Experian collects and aggregates information on over 1 billion people and businesses including 235 million individual U.S. consumers and more t ...
. The insurance reporting was phased out. The company also had a division selling specialist credit information to the insurance industry but spun off this service, including the Comprehensive Loss Underwriting Exchange (CLUE) database as
ChoicePoint LexisNexis Risk Solutions is a global data and analytics company that provides data and technology services, analytics, predictive insights and fraud prevention for a wide range of industries. It is headquartered in Alpharetta, Georgia (part of ...
in 1997. Equifax formerly offered digital certification services, which it sold to
GeoTrust GeoTrust is a digital certificate provider. The GeoTrust brand was bought by Symantec from Verisign in 2010, but agreed to sell the certificate business (including GeoTrust) in August 2017 to private equity and growth capital firm Thoma Bravo LL ...
in September 2001. Also in 2001, Equifax spun off its payment services division, forming the publicly listed company
Certegy Certegy was a public corporation created in 2001 when Equifax spun off their payment services division. The corporation had two divisions of its own: check verification and credit cards. In September 2005, a merger with Fidelity Information Serv ...
, which subsequently acquired
Fidelity National Information Services Fidelity National Information Services, Inc. (FIS) is an American multinational corporation which offers a wide range of financial products and services. FIS is most known for its development of Financial Technology, or FinTech, and as of Q2 202 ...
in 2006. Certegy effectively became a subsidiary of
Fidelity National Financial Fidelity National Financial, Inc. (NYSE: FNF), a Fortune 500 company, is a provider of title insurance and settlement services to the real estate and mortgage industries. FNF generated approximately $8.469 billion in annual revenue in 2019 fro ...
as a result of this reverse acquisition merger ''(See
Certegy Certegy was a public corporation created in 2001 when Equifax spun off their payment services division. The corporation had two divisions of its own: check verification and credit cards. In September 2005, a merger with Fidelity Information Serv ...
and
Fidelity National Information Services Fidelity National Information Services, Inc. (FIS) is an American multinational corporation which offers a wide range of financial products and services. FIS is most known for its development of Financial Technology, or FinTech, and as of Q2 202 ...
for further information)''. In October 2010, Equifax announced it was acquiring Anakam, an
identity verification An identity verification service is used by businesses to ensure that users or customers provide information that is associated with the identity of a real person. The service may verify the authenticity of physical identity documents such as a driv ...
software company headquartered in
San Diego, California San Diego ( , ; ) is a city on the Pacific Ocean coast of Southern California located immediately adjacent to the Mexico–United States border. With a 2020 population of 1,386,932, it is the eighth most populous city in the United States ...
, which invented and pioneered
SMS Short Message/Messaging Service, commonly abbreviated as SMS, is a text messaging service component of most telephone, Internet and mobile device systems. It uses standardized communication protocols that let mobile devices exchange short text ...
(text-message based)
two-factor authentication Multi-factor authentication (MFA; encompassing two-factor authentication, or 2FA, along with similar terms) is an electronic authentication method in which a user is granted access to a website or application only after successfully presenting ...
. Terms of the deal were not disclosed. Equifax purchased eThority, a
business intelligence Business intelligence (BI) comprises the strategies and technologies used by enterprises for the data analysis and management of business information. Common functions of business intelligence technologies include reporting, online analytical pr ...
(BI) company headquartered in
Charleston, South Carolina Charleston is the largest city in the U.S. state of South Carolina, the county seat of Charleston County, and the principal city in the Charleston–North Charleston metropolitan area. The city lies just south of the geographical midpoint o ...
, in October 2011. eThority is partnering with
TALX Equifax Workforce Solutions, formerly known as TALX (pronounced "talks"), is a wholly owned subsidiary of Equifax. It is based in St. Louis, Missouri. The company was originally founded in 1972 under the name Interface Technology Inc. The company ...
, a
St. Louis St. Louis () is the second-largest city in Missouri, United States. It sits near the confluence of the Mississippi and the Missouri Rivers. In 2020, the city proper had a population of 301,578, while the bi-state metropolitan area, which e ...
-based business unit of Equifax, and remained in Charleston. In February 2016, Equifax acquired the Australasian company
Veda FIle:Atharva-Veda samhita page 471 illustration.png, upright=1.2, The Vedas are ancient Sanskrit texts of Hinduism. Above: A page from the ''Atharvaveda''. The Vedas (, , ) are a large body of religious texts originating in ancient India. Co ...
, the largest
credit reference agency A credit bureau is a data collection agency that gathers account information from various creditors and provides that information to a consumer reporting agency in the United States, a credit reference agency in the United Kingdom, a credit repor ...
in Australia at the time. Veda had previously acquired the Australian
market research Market research is an organized effort to gather information about target markets and customers: know about them, starting with who they are. It is an important component of business strategy and a major factor in maintaining competitiveness. Mark ...
and
opinion poll An opinion poll, often simply referred to as a survey or a poll (although strictly a poll is an actual election) is a human research survey of public opinion from a particular sample. Opinion polls are usually designed to represent the opinions ...
ing company ReachTEL in September 2015., which continues to produce opinion polls in Australia. Equifax was the subject of more than 57,000 consumer complaints to the
Consumer Financial Protection Bureau The Consumer Financial Protection Bureau (CFPB) is an agency of the United States government responsible for consumer protection in the financial sector. CFPB's jurisdiction includes banks, credit unions, securities firms, payday lenders, mortg ...
from October 2012 to September 17, 2017, with most complaints relating to incomplete, inaccurate, outdated, or misattributed information held by the company. In September 2017, Equifax announced a cyber-security breach, which it claims to have occurred between mid-May and July 2017, where cybercriminals accessed approximately 145.5 million U.S. Equifax consumers' personal data, including their full names,
Social Security number In the United States, a Social Security number (SSN) is a nine-digit number issued to U.S. citizens, permanent residents, and temporary (working) residents under section 205(c)(2) of the Social Security Act, codified as . The number is issued to ...
s, birth dates, addresses, and driver license numbers. Equifax also confirmed at least 209,000 consumers' credit card credentials were taken in the attack. On March 1, 2018, Equifax announced that 2.4 million additional U.S. customers were affected by the breach, increasing the number of affected to 147.9 million Americans. The company claims to have discovered evidence of the cybercrime event on July 29, 2017. Residents in the
United Kingdom The United Kingdom of Great Britain and Northern Ireland, commonly known as the United Kingdom (UK) or Britain, is a country in Europe, off the north-western coast of the continental mainland. It comprises England, Scotland, Wales and North ...
(15.2 million) and
Canada Canada is a country in North America. Its ten provinces and three territories extend from the Atlantic Ocean to the Pacific Ocean and northward into the Arctic Ocean, covering over , making it the world's second-largest country by tot ...
(about 19,000) were also impacted. The vulnerability in which Chinese hackers leveraged was , the hackers managed to stay in Equifax systems undetected for approximately 134 days. In March 2018, the
Security and Exchange Commission The U.S. Securities and Exchange Commission (SEC) is an independent agency of the United States federal government, created in the aftermath of the Wall Street Crash of 1929. The primary purpose of the SEC is to enforce the law against market ...
accused Jun Ying, Equifax's former CIO, of illicit insider trading, by selling company stock before the breach was publicly disclosed. After an investigation by the
FBI The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and its principal Federal law enforcement in the United States, federal law enforcement age ...
, Ying pleaded guilty, was sentenced to four months of prison plus a year of supervised release, and was fined $55,000.00 and ordered to pay restitution of $117,117.61 in June 2019. An Equifax manager, Sudhakar Reddy Bonthu, also pleaded guilty to insider trading and received a sentence of 8 months of home confinement. In July 2019, ''
The New York Times ''The New York Times'' (''the Times'', ''NYT'', or the Gray Lady) is a daily newspaper based in New York City with a worldwide readership reported in 2020 to comprise a declining 840,000 paid print subscribers, and a growing 6 million paid ...
'', the ''
New York Post The ''New York Post'' (''NY Post'') is a conservative daily tabloid newspaper published in New York City. The ''Post'' also operates NYPost.com, the celebrity gossip site PageSix.com, and the entertainment site Decider.com. It was established ...
'' and other media reported Equifax had agreed to pay approximately $650 million to settle with the
Federal Trade Commission The Federal Trade Commission (FTC) is an independent agency of the United States government whose principal mission is the enforcement of civil (non-criminal) antitrust law and the promotion of consumer protection. The FTC shares jurisdiction ov ...
(FTC) to resolve investigations by several state attorneys general, the
Consumer Financial Protection Bureau The Consumer Financial Protection Bureau (CFPB) is an agency of the United States government responsible for consumer protection in the financial sector. CFPB's jurisdiction includes banks, credit unions, securities firms, payday lenders, mortg ...
, the FTC, and a consumer class-action lawsuit related to the data breach. By September 2019, however, Equifax had added qualifications and "hurdles" to its claims process which put in doubt whether the previously announced cash settlement of $125 per affected consumer would actually be awarded. On 19 December 2019, a federal judge in Atlanta awarded class-action attorneys representing consumers approximately $77.5 million, suggesting that individual consumers might expect to receive around six or seven dollars. In July 2020, Equifax reported that, after purchasing Ansonia Credit Data (Ansonia), a major source of consumer credit, payments, and invoice receivables (AR) data used by financial companies and other borrowers and businesses in the shipping and logistics sectors, the firm has expanded its position in commercial payment technology solutions. On 2 August 2022, a week after its CEO
Mark Begor Mark Begor (born c. 1959) is an American business executive. He is the CEO of Equifax. Early life Begor was born circa 1959. He graduated from Syracuse University with a bachelor's degree and earned a master in business administration from the Re ...
was deemed "uniquely qualified to lead the Company" and was granted a $25 million bonus package by Equifax's board, the
Wall Street Journal ''The Wall Street Journal'' is an American business-focused, international daily newspaper based in New York City, with international editions also available in Chinese and Japanese. The ''Journal'', along with its Asian editions, is published ...
reported that Equifax had sent millions of incorrectly calculated credit scores to lenders. Equifax acknowledged reporting inaccurate credit scores, but insisted the errors had affected only a few people. The following day, a class-action lawsuit was filed by Jacksonville, Florida resident Nydia Jenkins against Equifax alleging she had received a "substantially pricier car loan" (resulting in an additional loan payment of $2,352 more per year) due to Equifax reporting her credit score 130 points off from what it should have been.


Products

Equifax primarily operates in the
business-to-business Business-to-business (B2B or, in some countries, BtoB) is a situation where one business makes a commercial transaction with another. This typically occurs when: * A business is sourcing materials for their production process for output (e.g., a ...
sector, selling consumer credit and insurance reports and related analytics to businesses in a range of industries. Business customers include
retail Retail is the sale of goods and services to consumers, in contrast to wholesaling, which is sale to business or institutional customers. A retailer purchases goods in large quantities from manufacturers, directly or through a wholesaler, and t ...
ers,
insurance Insurance is a means of protection from financial loss in which, in exchange for a fee, a party agrees to compensate another party in the event of a certain loss, damage, or injury. It is a form of risk management, primarily used to hedge ...
firms,
healthcare provider A health care provider is an individual health professional or a health facility organization licensed to provide health care diagnosis and treatment services including medication, surgery and medical devices. Health care providers often receive ...
s, utilities, government agencies, as well as
bank A bank is a financial institution that accepts deposits from the public and creates a demand deposit while simultaneously making loans. Lending activities can be directly performed by the bank or indirectly through capital markets. Because ...
s,
credit union A credit union, a type of financial institution similar to a commercial bank, is a member-owned nonprofit organization, nonprofit financial cooperative. Credit unions generally provide services to members similar to retail banks, including depo ...
s, personal and specialty finance companies and other financial institutions. Equifax sells businesses credit reports, analytics,
demographic Demography () is the statistical study of populations, especially human beings. Demographic analysis examines and measures the dimensions and dynamics of populations; it can cover whole societies or groups defined by criteria such as edu ...
data, and software. Credit reports provide detailed information on the personal credit and payment history of individuals, indicating how they have honored financial obligations such as paying bills or repaying a
loan In finance, a loan is the lending of money by one or more individuals, organizations, or other entities to other individuals, organizations, etc. The recipient (i.e., the borrower) incurs a debt and is usually liable to pay interest on that d ...
. Credit grantors use this information to decide what sort of products or services to offer their customers, and on what terms. Equifax also provides commercial credit reports containing financial and non-financial data on businesses of all sizes. Equifax collects and provides data through the National Consumer Telecom and Utilities Exchange (NCTUE), an exchange of non-credit data including consumer payment history on telecommunications and utility accounts. In 1999, Equifax began offering services to the credit consumer sector in addition, such as credit fraud and identity theft prevention products. Equifax and other credit monitoring agencies are required by law to provide US residents with one free credit file disclosure every 12 months; the Annualcreditreport.com website incorporates data from U.S. Equifax credit records. Equifax also offers fraud prevention products based on
device fingerprinting A device fingerprint or machine fingerprint is information collected about the software and hardware of a remote computing device for the purpose of identification. The information is usually assimilated into a brief identifier using a fingerprinti ...
such as "FraudIQ Authenticate Device."


Security failings

According to senator Michael Crapo, "The amount of data that the private industry and Government collect and store is very concerning. There is intrinsic vulnerability in collecting and storing personal financial information, and we need to have a meaningful discussion on how to protect and limit access to it."


2016 advance-warnings of insecure systems

According to an October 2017 report from
Motherboard A motherboard (also called mainboard, main circuit board, mb, mboard, backplane board, base board, system board, logic board (only in Apple computers) or mobo) is the main printed circuit board (PCB) in general-purpose computers and other expand ...
, around December 2016, a security researcher examining Equifax's servers found that an online portal, created for Equifax employees only, was accessible to the open Internet. The same types of sensitive private information of American consumers (names, birth dates, social security numbers, etc.) were exposed as in the May–July breach, according to Motherboard. Additionally, the security researchers said they were able to gain
shell Shell may refer to: Architecture and design * Shell (structure), a thin structure ** Concrete shell, a thin shell of concrete, usually with no interior columns or exterior buttresses ** Thin-shell structure Science Biology * Seashell, a hard o ...
access on Equifax's servers and discovered and reported to Equifax additional vulnerabilities. According to the reporting, despite receiving this warning from the security researcher, the affected portal was not closed until six months later in June, well after the March and May–July breaches had begun. Moreover, the employee portal was reportedly not the same server targeted in the later breaches, which Motherboard speculates may suggest multiple breaches by more than one party may have occurred.


March 2017 security breach

On September 18, 2017, ''
Bloomberg News Bloomberg News (originally Bloomberg Business News) is an international news agency headquartered in New York City and a division of Bloomberg L.P. Content produced by Bloomberg News is disseminated through Bloomberg Terminals, Bloomberg Televi ...
'' reported that Equifax had been the victim of a "major breach of its computer systems" in March 2017, and that in early March it had begun "notifying a small number of outsiders and banking customers" about this attack.Riley, Michael, Anita Sharpe, and Jordan Robertson
"Equifax Suffered a Hack Almost Five Months Earlier Than the Date It Disclosed"
Bloomberg News Bloomberg News (originally Bloomberg Business News) is an international news agency headquartered in New York City and a division of Bloomberg L.P. Content produced by Bloomberg News is disseminated through Bloomberg Terminals, Bloomberg Televi ...
, September 18/19, 2017.
According to Bloomberg, a person familiar with the breach believed this early-March intrusion may have been carried out by the same party that breached Equifax's computer systems again in May. According to Bloomberg, Equifax enlisted
Mandiant Mandiant is an American cybersecurity firm and a subsidiary of Google. It rose to prominence in February 2013 when it released a report directly implicating China in cyber espionage. In December 2013, Mandiant was acquired by FireEye for $1 bi ...
(owned by
FireEye, Inc. Trellix (formerly FireEye and McAfee Enterprise) is a privately held cybersecurity company founded in 2022. It has been involved in the detection and prevention of major cyber attacks. It provides hardware, software, and services to investigat ...
) to assist in investigating the March attack. The same cybersecurity firm was hired following the May–July breach.


May–July 2017 data breach

Between May and July 2017, yet-identified hackers were able to use a known exploit on one of Equifax' web servers that had yet to be updated to access the credit records of more than 140 million Americans as well as some British and Canadian citizens before the breach was detected and shut down. Equifax disclosed the breach on September 7, 2017, after determining the means and scope of the breach. The event was considered "one of the biggest data breaches in history." Several consumers filed lawsuits in small-claims court against Equifax due to the breach, while Equifax later came to a $575 million settlement with the Federal Trade Commission to offer either a cash payment or credit monitoring for those affected by the breach. The data from the breach has yet to be seen on black markets or the dark web by security experts, making it difficult to identify the origin of the breach. However, in February 2020, the United States Department of Justice indicted four members of
China China, officially the People's Republic of China (PRC), is a country in East Asia. It is the world's most populous country, with a population exceeding 1.4 billion, slightly ahead of India. China spans the equivalent of five time zones and ...
's
People's Liberation Army The People's Liberation Army (PLA) is the principal military force of the People's Republic of China and the armed wing of the Chinese Communist Party (CCP). The PLA consists of five service branches: the Ground Force, Navy, Air Force, ...
on nine charges related to the breach, which China has denied.


2017 exposure of Argentine consumer data

In September 2017,
Brian Krebs Brian Krebs (born 1972) is an American journalist and investigative reporter. He is best known for his coverage of profit-seeking cybercriminals.Perlroth, Nicole.Reporting From the Web's Underbelly. ''The New York Times''. Retrieved February 28, ...
revealed that the Argentine arm of Equifax had left private data from approximately 14,000 consumers, and more than 100 staff members, available to anyone who entered "admin" as both the username and password for one of its online systems.


2017 withdrawal of vulnerable mobile apps

On September 7, 2017, the same day as Equifax announced a large security breach, Equifax removed its official
mobile app A mobile application or app is a computer program or software application designed to run on a mobile device such as a phone, tablet, or watch. Mobile applications often stand in contrast to desktop applications which are designed to run on d ...
s from the Apple
App Store An App Store (or app marketplace) is a type of digital distribution platform for computer software called applications, often in a mobile context. Apps provide a specific set of functions which, by definition, do not include the running of the co ...
and from
Google Play Google Play, also known as the Google Play Store and formerly the Android Market, is a digital distribution service operated and developed by Google. It serves as the official app store for certified devices running on the Android (operating sys ...
. While these apps themselves were not reportedly connected to that breach, they had security flaws of their own, being vulnerable to
man-in-the-middle attack In cryptography and computer security, a man-in-the-middle, monster-in-the-middle, machine-in-the-middle, monkey-in-the-middle, meddler-in-the-middle, manipulator-in-the-middle (MITM), person-in-the-middle (PITM) or adversary-in-the-middle (AiTM) ...
s owing to some parts using
HTTP The Hypertext Transfer Protocol (HTTP) is an application layer protocol in the Internet protocol suite model for distributed, collaborative, hypermedia information systems. HTTP is the foundation of data communication for the World Wide Web, ...
instead of
HTTPS Hypertext Transfer Protocol Secure (HTTPS) is an extension of the Hypertext Transfer Protocol (HTTP). It is used for secure communication over a computer network, and is widely used on the Internet. In HTTPS, the communication protocol is enc ...
.


2017 exposure of American salary data

On October 8, 2017, Krebs reported that
The Work Number The Work Number is an American employment verification database created in 1985 by Talx Corporation. Talx, (now Equifax Workforce Solutions) was acquired by Equifax Inc. in February 2007 for US$1.4 billion. Through The Work Number employers can ...
, a website operated by Equifax's
TALX Equifax Workforce Solutions, formerly known as TALX (pronounced "talks"), is a wholly owned subsidiary of Equifax. It is based in St. Louis, Missouri. The company was originally founded in 1972 under the name Interface Technology Inc. The company ...
division, exposed the salary histories for employees of tens of thousands of US companies to anyone in possession of the employee's
Social Security Number In the United States, a Social Security number (SSN) is a nine-digit number issued to U.S. citizens, permanent residents, and temporary (working) residents under section 205(c)(2) of the Social Security Act, codified as . The number is issued to ...
and date of birth. For roughly half the US population, both of the latter pieces of data are known to be in possession of criminals, following Equifax's May–July 2017 security breach. In July 2019, Equifax settled with the
Federal Trade Commission The Federal Trade Commission (FTC) is an independent agency of the United States government whose principal mission is the enforcement of civil (non-criminal) antitrust law and the promotion of consumer protection. The FTC shares jurisdiction ov ...
for $700 million. This number contains a $380,500,000 consumer restitution fund, part of the class action lawsuit.


Website malware

On October 12, 2017, Equifax's website was reported to have been offering visitors
malware Malware (a portmanteau for ''malicious software'') is any software intentionally designed to cause disruption to a computer, server, client, or computer network, leak private information, gain unauthorized access to information or systems, depri ...
via
drive-by download Drive-by download is of two types, each concerning the unintended download of computer software from the Internet: # Authorized drive-by downloads are downloads which a person has authorized but without understanding the consequences (e.g. down ...
. The malware was disguised as an update for
Adobe Flash Adobe Flash (formerly Macromedia Flash and FutureSplash) is a multimedia Computing platform, software platform used for production of Flash animation, animations, rich web applications, application software, desktop applications, mobile apps, mo ...
. At that time, only 3 out of 65 top anti-malware products provided protection against the particular malware, meaning that many visitors were at risk of having their computers infected if visiting the Equifax website. On October 13, 2017, the attack was revealed to have been performed by hijacking third-party
analytics Analytics is the systematic computational analysis of data or statistics. It is used for the discovery, interpretation, and communication of meaningful patterns in data. It also entails applying data patterns toward effective decision-making. It ...
JavaScript JavaScript (), often abbreviated as JS, is a programming language that is one of the core technologies of the World Wide Web, alongside HTML and CSS. As of 2022, 98% of Website, websites use JavaScript on the Client (computing), client side ...
from
Digital River Digital River is a private company that provides global e-commerce, payments and marketing services. In 2013, Digital River processed more than $30 billion in online transactions. Digital River is headquartered in Minnetonka, Minnesota. Compan ...
brand FireClick. Also on October 13, 2017, the
U.S. Internal Revenue Service The Internal Revenue Service (IRS) is the revenue service for the United States federal government, which is responsible for collecting U.S. federal taxes and administering the Internal Revenue Code, the main body of the federal statutory tax ...
was reported to have suspended a $7.2 million contract with Equifax, as a result of the attack.


Lawsuits and fines

The company has been fined by the Federal Trade Commission on two occasions for violating the Fair Credit Reporting Act ("FCRA"). In 2000, Equifax, along with Experian and TransUnion, was fined $2.5 million for blocking and delaying phone calls from consumers trying to get information about their credit. In 2003, the FTC took Equifax to court for the same reason and settled its lawsuit with the company for a fine of $250,000. In July 2013, a federal jury in Oregon awarded $18.6 million to Julie Miller of Marion County against Equifax for violations of the Fair Credit Reporting Act. In her lawsuit, Miller alleged Equifax had merged her credit reports with another person with a different Social Security number, date of birth, and address. Miller contacted Equifax repeatedly in writing and over the telephone, but Equifax refused to delete dozens of false collection accounts from Miller's credit report. The award included $18.4 million in punitive damages, and $180,000 in compensatory damages. Miller's lawyer, Justin Baxter, explained that the false reporting damaged Miller's reputation, she was denied credit, and her private information was given to businesses Miller had no relationship with. The jury's verdict is believed to be the largest award in an individual case under the Fair Credit Reporting Act. An Equifax spokesperson said that Equifax is considering appealing the jury's verdict. A federal judge reduced the award to $1.62 million in 2014. In 2014, Equifax and Heartland Bank were sued by Kimberly Haman of the St. Louis area for reporting she was dead. A Heartland Bank spokesperson said the bank "immediately investigated and contacted the credit reporting agencies after Haman reported" she was still alive. An Equifax "spokesperson told the Post-Dispatch that Equifax blocked the Heartland account information from appearing on Haman's credit report after a reporter's inquiry." In April 2014, Equifax was sued in New York federal court by God Gazarov, who claimed the company erroneously reports him as having no credit history because of his unusual first name. On November 4, 2017, it was reported that a group of five Oklahomans had sued the company, claiming that Equifax "violated laws which require financial institutions to protect the security of their customers' personal information." Equifax selected the law firm
DLA Piper DLA Piper is a multinational law firm with offices in over 40 countries throughout the Americas, Asia Pacific, Europe, Africa, and the Middle East. In 2021, it had a total revenue of US$3.47 billion, an average profit per equity partner of ...
to work on the case in D.C. It had turned to
Edelman Edelman is a surname. Notable people with the surname include: * Abram Wolf Edelman (a.k.a. Abraham Edelman; 1832–1907), Polish-born American rabbi; the first rabbi in Los Angeles, California * Adam Edelman (born 1991), American-born four-time Is ...
for earlier crisis control after the October 2017 privacy breach. Consumer lawsuits claiming damages under the FCRA have been successful in small claims court. Equifax software engineer Sudhakar Reddy was charged with
insider trading Insider trading is the trading of a public company's stock or other securities (such as bonds or stock options) based on material, nonpublic information about the company. In various countries, some kinds of trading based on insider information ...
for purchasing options prior to the disclosure of the 2017 data breach. In January 2020, Equifax agreed to a global settlement with the Federal Trade Commission, the Consumer Financial Protection Bureau, and 50 U.S. states and territories. For those that were affected by the data breach, there were open suggestions to file claims against it. The settlement includes up to $425 million to help people affected by the data breach. Equifax ultimately reached a settlement with regulators for up to $700 million.


See also

*
Compuscan Compuscan is a South African credit bureau that provides consumer and commercial credit information within South Africa and other African nations. Founded in 1994 and headquartered in Stellenbosch, South Africa, Compuscan is a subsidiary of So ...
*
Chinese cyberwarfare Cyberwarfare by China is the aggregate of all combative activities in the cyberspace which are taken by organs of the People's Republic of China, including affiliated advanced persistent threat groups, against other countries. Organization Wh ...
**
Chinese espionage in the United States The United States has often accused the government of the People's Republic of China of attempting to unlawfully acquire U.S. military technology and classified information as well as trade secrets of U.S. companiesFinkle, J. Menn, J., Viswan ...
*
Credit bureau A credit bureau is a data collection agency that gathers account information from various creditors and provides that information to a consumer reporting agency in the United States, a credit reference agency in the United Kingdom, a credit repor ...
*
Credit score A credit score is a numerical expression based on a level analysis of a person's credit files, to represent the creditworthiness of an individual. A credit score is primarily based on a credit report, information typically sourced from credit bu ...
*
Experian Experian is an American–Irish multinational data analytics and consumer credit reporting company. Experian collects and aggregates information on over 1 billion people and businesses including 235 million individual U.S. consumers and more t ...
*
Fair Credit Reporting Act The Fair Credit Reporting Act (FCRA), 15 U.S.C. § 1681 ''et seq'', is U.S. Federal Government legislation enacted to promote the accuracy, fairness, and privacy of consumer information contained in the files of consumer reporting agencies. It ...
*
Identity theft Identity theft occurs when someone uses another person's personal identifying information, like their name, identifying number, or credit card number, without their permission, to commit fraud or other crimes. The term ''identity theft'' was co ...
*
Innovis Innovis is the credit reporting division of CBC Companies and is considered the fourth largest consumer credit reporting agency in the United States, behind the “big three” Experian, TransUnion, and Equifax. Based in Columbus, Ohio, the co ...
*
Privacy laws of the United States Privacy laws of the United States deal with several different legal concepts. One is the ''invasion of privacy'', a tort based in common law allowing an aggrieved party to bring a lawsuit against an individual who unlawfully intrudes into thei ...
*
Talx Equifax Workforce Solutions, formerly known as TALX (pronounced "talks"), is a wholly owned subsidiary of Equifax. It is based in St. Louis, Missouri. The company was originally founded in 1972 under the name Interface Technology Inc. The company ...
*
The Work Number The Work Number is an American employment verification database created in 1985 by Talx Corporation. Talx, (now Equifax Workforce Solutions) was acquired by Equifax Inc. in February 2007 for US$1.4 billion. Through The Work Number employers can ...
*
TransUnion TransUnion is an American consumer credit reporting agency. TransUnion collects and aggregates information on over one billion individual consumers in over thirty countries including "200 million files profiling nearly every credit-active consum ...


References


External links

*
Equifax Consumer Identity Protection website

2019 Eligibility site related to 2017 data breach
{{Authority control Companies listed on the New York Stock Exchange American companies established in 1899 Financial services companies established in 1899 Financial services companies of the United States Former certificate authorities Companies based in Atlanta Corruption in the United States Credit scoring Data brokers