As my momma used to say "when it rains, it pours". If that's the case, Equifax is in the middle of a Hurricane Harvey-esque Cat 5 hurricane of pouring rain.
After "forgetting" to install a security patch to its website which led to the largest data breach in the history of ever, then "forgetting" to tell their 143 million victims that they are and will forever be at risk for identity theft for nearly two months, then "forgetting" to tell anyone about an earlier data breach that Equifax has now confirmed did indeed happen, but "remembering" to let their top execs know about both breaches so they could several million dollars worth of Equifax stock before Equifax stock priced dropped by over a third of its price and "remembering" to donate to their favorite Congressman Barry Loudermilk so he would propose a completely idiotic bill that would provide immense protection to Equifax and the other credit bureaus at the expense of his constituents and the rest of America, NOW it has come to light that, for approximately two weeks, Equifax has been sending victims to a fake website.
Yes, a fake website. A spoof. One that puts those victims at even greater risk of identity theft.
Instead of using its own website to help victims of its data breach, Equifax created a whole new site equifaxsecurity2017.com. Guess that added the year so they can keep their breaches straight. The problem with using a new website instead of their existing one is that phishers and scammers can much more easily create fake websites using variations of the legitimate website's address. This would include reversing the order of the words or making sites with common typos of the real site name. In this instance, a mere day after the launch of the legitimate site, scammers had created 194 phishing websites that used addresses similar to the legitimate site.
What's worse than Equifax's boneheaded move in creating a new site instead of using its own Equifax.com site? Equifax directed victims of its data breach to the WRONG site. On three separate occasions, Equifax tweeted the incorrect URL securityequifax2017.com for its victims to use. Two of the tweets occurred on September 9 and the last on September 18 (i.e. three days ago!).
The Fair Credit Reporting Act requires consumer reporting agencies such as Equifax to follow reasonable procedures to assure maximum possible accuracy of the credit reports they generate regarding consumers. I have been suing Equifax for 18 years for violating that section by failing to have, much less follow, reasonable procedures to assure maximum possible accuracy. Now the public is getting a taste of what I have been seeing for years ... ignorance on top of ineptitude.
Please remember this if and when your Congressman or Senator votes in favor of Barry Loudermilk's bill designed to harm consumers by protecting Equifax from its own gross negligence and boneheadedness.
Custom Search
Showing posts with label HR 2359. Show all posts
Showing posts with label HR 2359. Show all posts
September 21, 2017
September 19, 2017
It Just Keeps Getting Deeper - Equifax Suffered Second Undisclosed Data Breach
Bloomberg.com is reporting that the gigantically huge data breach that Equifax disclosed less than two weeks ago is not the only hack the consumer reporting agency suffered this year. There was allegedly a hack in March, two or more months before the big data breach that has put 143 million Americans at risk of having their identities stolen and their lives ruined.
According to Bloomberg, Equifax notified a small number of outsiders and banking customers in early March that it had suffered a breach. At that time, Equifax brought in a security firm to determine the scope of the breach. What Equifax did not do was tell the general public about the first data breach, either then or in July when it learned of the second, larger breach.
The second, big breach occurred (according to Equifax) when hackers gained access to Equifax's computer system through a known flaw in the company's web software that somehow was not patched until after the breach was discovered in late July. Was the flaw in the system discovered by the security firm in March and Equifax negligently failed to implement the patch to fix the vulnerability?
While the Bloomberg article focuses on the first hack's implications for the three executives that dumped Equifax stock after the second breach was known by Equifax but before the public was informed and the subsequent stock price drop, one thing the article does not mention is how the timing of the first hack completely undermines Representative Loudermilk's claim that his Equifax protection bill was drafted before the Equifax data breach, not in response to it. I posted about Loudermilk's position yesterday.
Loudermilk introduced his bill designed to protect Equifax and the other credit bureaus and hurt consumers (such as his constituents) in May, a few weeks before the second breach allegedly occurred. However, now that we know that Equifax knew of the first breach in March, why would we think that Loudermilk was not attempting to shield Equifax, a donor to his campaign, from liability from the first breach by pushing a bill that does nothing but protect the credit bureau from having to pay for its malfeasance? The timeline is looking very bad for both Equifax and Loudermilk. If I were a citizen of the 11th Congressional District of Georgia, I would have some very serious doubts about where my congressman's loyalties lie.
According to Bloomberg, Equifax notified a small number of outsiders and banking customers in early March that it had suffered a breach. At that time, Equifax brought in a security firm to determine the scope of the breach. What Equifax did not do was tell the general public about the first data breach, either then or in July when it learned of the second, larger breach.
The second, big breach occurred (according to Equifax) when hackers gained access to Equifax's computer system through a known flaw in the company's web software that somehow was not patched until after the breach was discovered in late July. Was the flaw in the system discovered by the security firm in March and Equifax negligently failed to implement the patch to fix the vulnerability?
While the Bloomberg article focuses on the first hack's implications for the three executives that dumped Equifax stock after the second breach was known by Equifax but before the public was informed and the subsequent stock price drop, one thing the article does not mention is how the timing of the first hack completely undermines Representative Loudermilk's claim that his Equifax protection bill was drafted before the Equifax data breach, not in response to it. I posted about Loudermilk's position yesterday.
Loudermilk introduced his bill designed to protect Equifax and the other credit bureaus and hurt consumers (such as his constituents) in May, a few weeks before the second breach allegedly occurred. However, now that we know that Equifax knew of the first breach in March, why would we think that Loudermilk was not attempting to shield Equifax, a donor to his campaign, from liability from the first breach by pushing a bill that does nothing but protect the credit bureau from having to pay for its malfeasance? The timeline is looking very bad for both Equifax and Loudermilk. If I were a citizen of the 11th Congressional District of Georgia, I would have some very serious doubts about where my congressman's loyalties lie.
September 18, 2017
Representative Loudermilk is STILL trying to protect Equifax instead of consumers
U.S. Representative Barry Loudermilk is still trying to give immunity to Equifax for its utter failure to protect the private information of over 143 million Americans and its subsequent bungling of the data breach it allowed to happen.
Prior to the breach (allegedly, since we really don't know when the breach actually happened since we only have Equifax's word that the breach occurred in late May through early June), Representative Loudermilk, who is a U.S. Representative from Georgia, the home state of Equifax, proposed legislation that, if passed, would gut the protections afforded consumers by the Fair Credit Reporting Act. The proposed legislation, H.R. 2359, would change the Fair Credit Reporting Act in two ways, both of which are very damaging to consumers and, not by coincidence, very favorable to Equifax and the other credit bureaus.
First, it would eliminate punitive damages. Yes, the one thing that big corporations like Equifax are scared of is a punitive damage award. Their profits are soooo great that an award of just compensatory damages will never be enough for them to really notice in the long term. Punitive damages, however, are used to punish a corporation for its wrongdoing. Equifax, as seen by its shenanigans of first hiding the data breach and then trying to pull a fast one to get its victims to give up their right to sue, is up to its eyeballs in wrongdoing. Equifax's conduct is the type of conduct that deserves a punitive damages award against it, since their conduct is willful, intentional and not just a mere accident or negligent mishap. So H.R. 2359 would benefit Equifax in that way.
Further, and more importantly in the context of consumers getting justice for Equifax's negligently allowing the data breach to happen, H.R. 2359 caps what consumers can get via a class action at $500,000. Not per consumer, per class action. And, since all of the approximately 100 class actions filed against Equifax for the data breach will ultimately be merged into one big class, that means 143 million plus victims of the data breach (less those who wisely opt out and file individual lawsuits) will have to split a measly $500,000 if Representative Loudermilk's bill becomes law. If my math is correct, that is roughly 3 cents per victim. Yes, three cents. Three shiny pennies. How is that justice?!
And, instead of backing away from his bill like its a grenade about to explode, Representative Loudermilk released the following statement:
"The data breach at Equifax has placed an unimaginable number of Americans’ personal information at serious risk. Not only must Equifax be held accountable for the breach of their systems, they must also be held accountable for their failure to notify the public of the breach in a timely manner. Businesses such as Equifax that obtain and store massive amounts of information on individuals must be held to the highest data protection standards. I will be working with the Financial Services Committee on investigating this data breach and the inadequate response of Equifax executives. Furthermore, we have already begun working on legislation mandating businesses to notify consumers affected by data breaches in a timely manner.
"Unfortunately, the outrage that followed the announcement by Equifax caused a gross mischaracterization of a bill that I have been working on since early this year. It was falsely reported that this bill (H.R. 2359) was introduced to give immunity to Equifax from any liability over this data breach. This couldn't be further from the truth. The FCRA Liability Harmonization Act (H.R. 2359) was introduced back in May, and is aimed at curbing frivolous class action lawsuits against businesses under the Fair Credit Reporting Act (FCRA). The businesses affected by FCRA lawsuits include community banks, credit unions, auto dealerships, retailers, and many other small businesses that extend credit to consumers.
"Reports that this bill would grant any immunity to Equifax for liability in this data breach are completely false. The bill does not give any immunity from prosecution or civil lawsuits for wrongdoing to any business. Furthermore, data breaches are governed by state laws, not the FCRA, so this bill would not apply to Equifax in this case at all with respect to the 143 million people whose personally identifiable information was compromised.
"Finally, given the unfounded attacks on me and the rampant misinformation circulating about this legislation, the Financial Services Committee has not scheduled further action on any bill at this time."
So Representative Loudermilk is claiming that his bill would not grant immunity to Equifax? While technically true, being capped at paying three cents a victim is about as close to immunity as one can get. For Representative Loudermilk to make this grossly misleading statement is deplorable. He obviously cares more about Equifax, his campaign donor, than he does about consumers, including his constituents. I hope the people of the 11th Congressional District of Georgia are paying attention to whose side Mr. Loudermilk is one, because it sure isn't theirs.
Prior to the breach (allegedly, since we really don't know when the breach actually happened since we only have Equifax's word that the breach occurred in late May through early June), Representative Loudermilk, who is a U.S. Representative from Georgia, the home state of Equifax, proposed legislation that, if passed, would gut the protections afforded consumers by the Fair Credit Reporting Act. The proposed legislation, H.R. 2359, would change the Fair Credit Reporting Act in two ways, both of which are very damaging to consumers and, not by coincidence, very favorable to Equifax and the other credit bureaus.
First, it would eliminate punitive damages. Yes, the one thing that big corporations like Equifax are scared of is a punitive damage award. Their profits are soooo great that an award of just compensatory damages will never be enough for them to really notice in the long term. Punitive damages, however, are used to punish a corporation for its wrongdoing. Equifax, as seen by its shenanigans of first hiding the data breach and then trying to pull a fast one to get its victims to give up their right to sue, is up to its eyeballs in wrongdoing. Equifax's conduct is the type of conduct that deserves a punitive damages award against it, since their conduct is willful, intentional and not just a mere accident or negligent mishap. So H.R. 2359 would benefit Equifax in that way.
Further, and more importantly in the context of consumers getting justice for Equifax's negligently allowing the data breach to happen, H.R. 2359 caps what consumers can get via a class action at $500,000. Not per consumer, per class action. And, since all of the approximately 100 class actions filed against Equifax for the data breach will ultimately be merged into one big class, that means 143 million plus victims of the data breach (less those who wisely opt out and file individual lawsuits) will have to split a measly $500,000 if Representative Loudermilk's bill becomes law. If my math is correct, that is roughly 3 cents per victim. Yes, three cents. Three shiny pennies. How is that justice?!
And, instead of backing away from his bill like its a grenade about to explode, Representative Loudermilk released the following statement:
"The data breach at Equifax has placed an unimaginable number of Americans’ personal information at serious risk. Not only must Equifax be held accountable for the breach of their systems, they must also be held accountable for their failure to notify the public of the breach in a timely manner. Businesses such as Equifax that obtain and store massive amounts of information on individuals must be held to the highest data protection standards. I will be working with the Financial Services Committee on investigating this data breach and the inadequate response of Equifax executives. Furthermore, we have already begun working on legislation mandating businesses to notify consumers affected by data breaches in a timely manner.
"Unfortunately, the outrage that followed the announcement by Equifax caused a gross mischaracterization of a bill that I have been working on since early this year. It was falsely reported that this bill (H.R. 2359) was introduced to give immunity to Equifax from any liability over this data breach. This couldn't be further from the truth. The FCRA Liability Harmonization Act (H.R. 2359) was introduced back in May, and is aimed at curbing frivolous class action lawsuits against businesses under the Fair Credit Reporting Act (FCRA). The businesses affected by FCRA lawsuits include community banks, credit unions, auto dealerships, retailers, and many other small businesses that extend credit to consumers.
"Reports that this bill would grant any immunity to Equifax for liability in this data breach are completely false. The bill does not give any immunity from prosecution or civil lawsuits for wrongdoing to any business. Furthermore, data breaches are governed by state laws, not the FCRA, so this bill would not apply to Equifax in this case at all with respect to the 143 million people whose personally identifiable information was compromised.
"Finally, given the unfounded attacks on me and the rampant misinformation circulating about this legislation, the Financial Services Committee has not scheduled further action on any bill at this time."
So Representative Loudermilk is claiming that his bill would not grant immunity to Equifax? While technically true, being capped at paying three cents a victim is about as close to immunity as one can get. For Representative Loudermilk to make this grossly misleading statement is deplorable. He obviously cares more about Equifax, his campaign donor, than he does about consumers, including his constituents. I hope the people of the 11th Congressional District of Georgia are paying attention to whose side Mr. Loudermilk is one, because it sure isn't theirs.
September 08, 2017
Equifax based in Georgia; Georgian Congressman seeks to gut FCRA. Coincidence? I think not!
Equifax is based in Atlanta, Georgia. Three guesses which state's congressman proposed HR 2359, i.e. the Kill the FCRA bill. Yep, that's right, Congressman Loudermilk of Georgia. I wonder who put him up to it?
Representative Loudermilk is now being called on to withdraw his Equifax protecting bill by the National Association of Consumer Advocates (of which I am a proud member) and The Georgia Watch. Their press release reads:
"NACA, Georgia Watch Call on Rep. Loudermilk of Georgia to Withdraw His Bill That Favors Equifax, Credit Bureaus Over Harmed Consumers
In light of the astonishing announcement of credit reporting agency Equifax’s security breach which impacts the personal information of more than 140 million consumers, National Association of Consumer Advocates and Georgia Watch call on Rep. Barry Loudermilk (R-Ga.) to withdraw his legislation, H.R. 2359, that would drastically reduce remedies for consumers who are victims of credit reporting abuses.
On the same day that Equifax announced the massive data breach, a subcommittee of the U.S. House Financial Services Committee held a hearing to consider legislation, including Loudermilk’s bill that would amend the federal Fair Credit Reporting Act to essentially shield credit reporting agencies from full accountability for willful and reckless conduct that upends individuals’ employment and financial lives.
Specifically, the “FCRA Liability Harmonization Act” would eliminate punitive damages, a tool used to punish the worst actors, and would impose an arbitrary $500,000 limit on statutory and actual damages in class actions. These illogical blocks on consumer remedies would obstruct individuals’ legal rights.
“Instead of running to Congress to seek a “get out of jail free” card to avoid accountability for its reckless handling of consumers’ personal and financial information, Equifax and its counterparts in the credit reporting industry should focus on protecting information from identity thieves,” said Christine Hines, legislative director at National Association of Consumer Advocates (NACA).
At Thursday’s hearing, witnesses for the credit reporting industry claimed that their violations of federal protections were merely technical and do not harm anyone despite evidence that consumers have been blocked from accessing credit, housing, and jobs due to industry’s irresponsible handling of consumer information. Industry representatives also used the hearing to bash a rule issued by the Consumer Financial Protection Bureau that would restore consumers’ ability to band together in class actions when harmed by unlawful financial industry practices.
Currently Equifax is rightly being criticized for its handling of the massive data breach. One of many of its missteps – it has inserted forced arbitration clauses in the terms and conditions of various credit monitoring services that it is encouraging affected consumers to enroll in.
“Equifax’s use of forced arbitration clauses and class action bans means that consumers cannot band together in court to seek remedies against it,” said Liz Coyle, executive director of Georgia Watch. “This is unacceptable and will have disastrous effects on the marketplace.”
NACA and Georgia Watch insist that Rep. Loudermilk withdraw his bill and support consumers’ right to hold bad actors like Equifax fully accountable through the justice system."
Representative Loudermilk is now being called on to withdraw his Equifax protecting bill by the National Association of Consumer Advocates (of which I am a proud member) and The Georgia Watch. Their press release reads:
"NACA, Georgia Watch Call on Rep. Loudermilk of Georgia to Withdraw His Bill That Favors Equifax, Credit Bureaus Over Harmed Consumers
In light of the astonishing announcement of credit reporting agency Equifax’s security breach which impacts the personal information of more than 140 million consumers, National Association of Consumer Advocates and Georgia Watch call on Rep. Barry Loudermilk (R-Ga.) to withdraw his legislation, H.R. 2359, that would drastically reduce remedies for consumers who are victims of credit reporting abuses.
On the same day that Equifax announced the massive data breach, a subcommittee of the U.S. House Financial Services Committee held a hearing to consider legislation, including Loudermilk’s bill that would amend the federal Fair Credit Reporting Act to essentially shield credit reporting agencies from full accountability for willful and reckless conduct that upends individuals’ employment and financial lives.
Specifically, the “FCRA Liability Harmonization Act” would eliminate punitive damages, a tool used to punish the worst actors, and would impose an arbitrary $500,000 limit on statutory and actual damages in class actions. These illogical blocks on consumer remedies would obstruct individuals’ legal rights.
“Instead of running to Congress to seek a “get out of jail free” card to avoid accountability for its reckless handling of consumers’ personal and financial information, Equifax and its counterparts in the credit reporting industry should focus on protecting information from identity thieves,” said Christine Hines, legislative director at National Association of Consumer Advocates (NACA).
At Thursday’s hearing, witnesses for the credit reporting industry claimed that their violations of federal protections were merely technical and do not harm anyone despite evidence that consumers have been blocked from accessing credit, housing, and jobs due to industry’s irresponsible handling of consumer information. Industry representatives also used the hearing to bash a rule issued by the Consumer Financial Protection Bureau that would restore consumers’ ability to band together in class actions when harmed by unlawful financial industry practices.
Currently Equifax is rightly being criticized for its handling of the massive data breach. One of many of its missteps – it has inserted forced arbitration clauses in the terms and conditions of various credit monitoring services that it is encouraging affected consumers to enroll in.
“Equifax’s use of forced arbitration clauses and class action bans means that consumers cannot band together in court to seek remedies against it,” said Liz Coyle, executive director of Georgia Watch. “This is unacceptable and will have disastrous effects on the marketplace.”
NACA and Georgia Watch insist that Rep. Loudermilk withdraw his bill and support consumers’ right to hold bad actors like Equifax fully accountable through the justice system."
Congressional Committee to hold Hearing Regarding Equifax Data Breach
Yesterday, the House Financial Services Committee held a hearing on a bill that would gut the protections of the Fair Credit Reporting Act, which is the only law protecting Americans from the ridiculously inept consumer reporting agencies such as Equifax.
Today, the public learned of a massive data breach of Equifax's treasure trove of secret information regarding consumers, including the full names, Social Security numbers, dates of birth and addresses of approximately 143 Americans.
Now, the House Financial Services Committee released the following press release:
"WASHINGTON – House Financial Services Committee Chairman Jeb Hensarling (R-TX) said his committee will hold a hearing on the Equifax data breach that has potentially compromised the personal information of roughly 143 million Americans.
“This is obviously a very serious and very troubling situation and our committee has already begun preparations for a hearing. Large-scale security breaches are becoming all too common. Every breach leaves consumers exposed and vulnerable to identity theft, fraud and a host of other crimes, and they deserve answers,” said Chairman Hensarling.
A date for the hearing will be announced at a later time."
Chairman Hensarling, if you want to protect Americans from data breaches and the damage caused by identity theft, your first step should be to kill HR 2359. Only the Fair Credit Reporting Act stands in the way of Equifax and the other credit bureaus harming Americans by willfully and knowingly reporting erroneous information on Americans' credit reports. That is the "answer" you seek. Have you hearing, but start with killing HR 2359 and let the Fair Credit Reporting Act continue to protect Americans.
Today, the public learned of a massive data breach of Equifax's treasure trove of secret information regarding consumers, including the full names, Social Security numbers, dates of birth and addresses of approximately 143 Americans.
Now, the House Financial Services Committee released the following press release:
"WASHINGTON – House Financial Services Committee Chairman Jeb Hensarling (R-TX) said his committee will hold a hearing on the Equifax data breach that has potentially compromised the personal information of roughly 143 million Americans.
“This is obviously a very serious and very troubling situation and our committee has already begun preparations for a hearing. Large-scale security breaches are becoming all too common. Every breach leaves consumers exposed and vulnerable to identity theft, fraud and a host of other crimes, and they deserve answers,” said Chairman Hensarling.
A date for the hearing will be announced at a later time."
Chairman Hensarling, if you want to protect Americans from data breaches and the damage caused by identity theft, your first step should be to kill HR 2359. Only the Fair Credit Reporting Act stands in the way of Equifax and the other credit bureaus harming Americans by willfully and knowingly reporting erroneous information on Americans' credit reports. That is the "answer" you seek. Have you hearing, but start with killing HR 2359 and let the Fair Credit Reporting Act continue to protect Americans.
Subscribe to:
Posts (Atom)