equifax logo

Equifax Will Pay At Least $650 Million In Settlement Over 2017 Data Breach

The credit-reporting agency will pay at least $300 million to victims. But it may be difficult for consumers to prove direct losses from identity theft.

Equifax, one of the country’s three major credit-reporting agencies, could pay over $700 million⁠—and will pay at least $650 million⁠—to settle federal, state and consumer lawsuits brought after the sensitive information of more than 147 million people was exposed in a data breach in 2017.

The settlement, which ends pending class-action lawsuits and investigations into the company by the Federal Trade Commission, state attorneys general and the Consumer Financial Protection Bureau, is the largest ever for a data breach. A court still needs to approve the terms of the settlement, The New York Times reported.

If the deal goes through, Equifax will pay $175 million in fines to all 50 states and $100 million to the CFPB, according to CNBC. From there, the company will establish a $380.5 million restitution fund for consumers affected by the breach. A portion of those funds will go to lawyers fees, but at least $300 million must go to victims of the incident, the Times reported.

Depending on how many people are able to demonstrate they were directly harmed by the breach, Equifax will be required to add up to $125 million to the fund and potentially pay over $500 million to consumers alone.

Since the breach was made public in September 2017, lawmakers and regulators have scrutinized Equifax for its slow response to the attack and lax security policies. As part of the deal, the company agreed to improve its security and have its policies evaluated regularly by an outside party. The hackers behind the cyber attack have still not been identified by law enforcement.

“We can be confident that a large number of the compromised users’ sensitive information from the Equifax breach is still actively in use in account takeover attacks,” Deepak Patel, a security evangelist with cybersecurity company PerimeterX, said. “Cybercriminals can combine data from different breaches - for example, name and address from one with the date of birth and password from another - to increase the success rate of credential stuffing.”

After a court order approves the settlement, consumers will be able to file for free credit monitoring and identity restoration services through an official website. In addition, people directly affected by the breach can submit documents showing the misuse of their personal information, their out-of-pocket losses and expenses related to credit or identity monitoring services. Equifax will pay up to $20,000 for those claims.

But it may be difficult to prove direct losses from identity theft, particularly because information stolen via the Equifax breach has never been found for sale on the dark web, according to CNBC. The New York Attorney General’s office said it will enforce a rule that allows Americans who have been the victim of identity theft from any breach after the Equifax incident to apply for out-of-pocket reimbursements.

In order to qualify, consumers will need a paper trail proving lost funds and time they spent filing disputes over the theft. The time spent dealing with the breach will be compensated at $25 per hour for up to 20 hours, CNBC reported.

“Equifax put profits over privacy and greed over people, and must be held accountable to the millions of people they put at risk,” Letitia James, the New York attorney general, said in a statement. “Now it’s time for the company to do what’s right and not only pay restitution to the millions of victims of their data breach, but also provide every American who had their highly sensitive information accessed with the tools they need to battle identity theft in the future.”

Massive corporate data breaches are now regular events around the world, and other companies are facing stiff penalties from government regulators. British Airways and Mariott International were recently hit with record fines under the General Data Protection Regulation law that went into effect in 2018.

“When the Equifax and British Airways breaches happened in 2017, it seemed like regulators would let them off easy with a slap on the wrist,” Patel said. “But the FTC and GDPR are imposing meaningful fines to hold these large corporations accountable for breaches involving sensitive user data.”

Featured

  • Keynote Speakers Announced for ISC West 2025

    ISC West, hosted in collaboration with premier sponsor the Security Industry Association (SIA), unveiled its 2025 Keynote Series. Featuring a powerhouse lineup of experts in cybersecurity, retail security, and leadership, each keynote will offer invaluable insights into the challenges and opportunities transforming the field of security. Read Now

    • Industry Events
    • ISC West
  • Study: Video Doorbells Have a 71% Service Attach Rate

    Parks Associates recently announced a new white paper, Consumer IoT Product Development: Managing Costs, Optimizing Revenues, which provides companies with a business-planning blueprint to evaluate how a consumer IoT solution will perform across its lifetime. Subscription services, such as video storage and professional monitoring, can be critical for covering ongoing cloud and support costs Read Now

  • Michigan City Fights Retail Crime With AI-Powered Video Surveillance, 911 Camera Sharing

    To combat persistent retail crime and deliver peace of mind to workers in the bustling North Leroy Street business district, the City of Fenton Police Department has deployed a new AI-powered video surveillance system with camera-sharing technology to accelerate response time during retail heists or other emergencies. Read Now

  • TSA Intercepts 6,678 Firearms at Airport Security Checkpoints in 2024

    During 2024, the Transportation Security Administration (TSA) intercepted a total of 6,678 firearms at airport security checkpoints, preventing them from getting into the secure areas of the airport and onboard aircraft. Approximately 94% of these firearms were loaded. This total is a minor decrease from the 6,737 firearms stopped in 2023. Throughout 2024, TSA managed its “Prepare, Pack, Declare” public awareness campaign to explain the steps for safely traveling with a firearm. Read Now

Featured Cybersecurity

Webinars

New Products

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure. 3

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis. 3

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions. 3