equifax logo

Equifax Will Pay At Least $650 Million In Settlement Over 2017 Data Breach

The credit-reporting agency will pay at least $300 million to victims. But it may be difficult for consumers to prove direct losses from identity theft.

Equifax, one of the country’s three major credit-reporting agencies, could pay over $700 million⁠—and will pay at least $650 million⁠—to settle federal, state and consumer lawsuits brought after the sensitive information of more than 147 million people was exposed in a data breach in 2017.

The settlement, which ends pending class-action lawsuits and investigations into the company by the Federal Trade Commission, state attorneys general and the Consumer Financial Protection Bureau, is the largest ever for a data breach. A court still needs to approve the terms of the settlement, The New York Times reported.

If the deal goes through, Equifax will pay $175 million in fines to all 50 states and $100 million to the CFPB, according to CNBC. From there, the company will establish a $380.5 million restitution fund for consumers affected by the breach. A portion of those funds will go to lawyers fees, but at least $300 million must go to victims of the incident, the Times reported.

Depending on how many people are able to demonstrate they were directly harmed by the breach, Equifax will be required to add up to $125 million to the fund and potentially pay over $500 million to consumers alone.

Since the breach was made public in September 2017, lawmakers and regulators have scrutinized Equifax for its slow response to the attack and lax security policies. As part of the deal, the company agreed to improve its security and have its policies evaluated regularly by an outside party. The hackers behind the cyber attack have still not been identified by law enforcement.

“We can be confident that a large number of the compromised users’ sensitive information from the Equifax breach is still actively in use in account takeover attacks,” Deepak Patel, a security evangelist with cybersecurity company PerimeterX, said. “Cybercriminals can combine data from different breaches - for example, name and address from one with the date of birth and password from another - to increase the success rate of credential stuffing.”

After a court order approves the settlement, consumers will be able to file for free credit monitoring and identity restoration services through an official website. In addition, people directly affected by the breach can submit documents showing the misuse of their personal information, their out-of-pocket losses and expenses related to credit or identity monitoring services. Equifax will pay up to $20,000 for those claims.

But it may be difficult to prove direct losses from identity theft, particularly because information stolen via the Equifax breach has never been found for sale on the dark web, according to CNBC. The New York Attorney General’s office said it will enforce a rule that allows Americans who have been the victim of identity theft from any breach after the Equifax incident to apply for out-of-pocket reimbursements.

In order to qualify, consumers will need a paper trail proving lost funds and time they spent filing disputes over the theft. The time spent dealing with the breach will be compensated at $25 per hour for up to 20 hours, CNBC reported.

“Equifax put profits over privacy and greed over people, and must be held accountable to the millions of people they put at risk,” Letitia James, the New York attorney general, said in a statement. “Now it’s time for the company to do what’s right and not only pay restitution to the millions of victims of their data breach, but also provide every American who had their highly sensitive information accessed with the tools they need to battle identity theft in the future.”

Massive corporate data breaches are now regular events around the world, and other companies are facing stiff penalties from government regulators. British Airways and Mariott International were recently hit with record fines under the General Data Protection Regulation law that went into effect in 2018.

“When the Equifax and British Airways breaches happened in 2017, it seemed like regulators would let them off easy with a slap on the wrist,” Patel said. “But the FTC and GDPR are imposing meaningful fines to hold these large corporations accountable for breaches involving sensitive user data.”

Featured

  • 2024 Gun Violence Report: Fewer Overall Incidents, but School Deaths and Injuries Are on the Rise

    Omnilert, provider of gun detection technology, today released its compilation of Gun Violence Statistics for 2024 summarizing gun violence tragedies and their adverse effects on Americans and the economy. While research showed a decrease in overall deaths and injuries, the rising number of school shootings and fatalities and high number of mass shootings underscored the need to keep more people safe in schools as well as places of worship, healthcare, government, retail and commerce, finance and banking, hospitality and other public places. Read Now

  • Survey: Only 7 Percent of Business Leaders Using AI in Physical Security

    A new survey from Pro-Vigil looks at video surveillance trends, how AI is impacting physical security, and more. Read Now

  • MetLife Stadium Uses Custom Surveillance Solution from Axis Communications

    Axis Communications, provider of video surveillance and network devices, today announced the implementation of a custom surveillance solution developed in collaboration with the MetLife Stadium security team. This new, tailored solution will help the venue augment its security capabilities, providing high-quality video at unprecedented distances and allowing the security team to identify details from anywhere in the venue. Read Now

  • U.S. Cyber Trust Mark Launches for Consumer Internet-Connected Devices

    The White House recently announced the launch of a cybersecurity label for internet-connected devices, known as the U.S. Cyber Trust Mark, completing public notice and input over the last 18 months. During that time, FCC Commissioners decided in a bipartisan and unanimous vote to authorize the program and adopt final rules, as well as the trademarked, distinct shield logo that will be applied to products certified for the U.S. Cyber Trust Mark label. Read Now

Featured Cybersecurity

Webinars

New Products

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction. 3

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles. 3

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis. 3