Equifax raises breach victim number to 145.5 million

October 3, 2017

Equifax said Monday an investigation into the massive data breach at the credit agency discovered 2.5 million additional potential victims, bringing the total to 145.5 million.

Interim chief executive Paulino do Rego Barros, made the disclosure in a statement, saying, "Our priorities are transparency and improving support for consumers. I will continue to monitor our progress on a daily basis."

The statement said the cybersecurity firm Mandiant made the new estimate after a forensic review of the incident, which is believed to be one of the worst breaches because of the sensitivity of data leaked.

The review "also has concluded that there is no evidence the attackers accessed databases located outside of the United States," the Equifax statement said.

Mandiant found that about 8,000 Canadian consumers were impacted by the hack, fewer than the initial estimate of 100,000. The company said a review of the impact on British consumers was still being analyzed.

Separately Monday, former CEO Richard Smith said in testimony prepared for a congressional hearing that the security team at Equifax failed to patch a vulnerability in March after getting a warning about the flaw.

Smith, in a statement to a congressional committee released, offered a timeline of the cyber attack which leaked and other sensitive data.

Smith said in prepared remarks to a House panel that the company on March 9 circulated an internal memo warning about a software flaw identified by the government's Computer Emergency Response Team (CERT).

He added that Equifax policy would have required a patch to be applied within 48 hours and that this was not done—but he could not explain why.

Equifax's information security department ran scans that should have identified any systems that were vulnerable but failed to identify any flaws in the software known as Apache Struts.

"I understand that Equifax's investigation into these issues is ongoing," he said in the statement.

"The company knows, however, that it was this unpatched vulnerability that allowed hackers to access personal identifying information."

Smith said he was notified of the breach on July 31, but was not aware "of the scope of this attack." He informed the company's lead director three weeks later, on August 22, and board meetings were held on the matter August 24 and 25.

Equifax, one of the major agencies gathering data used in credit ratings for banks, has come under fire for waiting until September 7 to publicly disclose the breach, and investigators are looking into stock sales by two senior executives in August.

Smith stepped down last week amid the investigation, while indicating he would remain in a consulting capacity during the investigation, which includes a congressional hearing Tuesday.

Smith offered a fresh apology for the attack, saying in his statement: "As CEO I was ultimately responsible for what happened on my watch. Equifax was entrusted with Americans' private data and we let them down.

Explore further: Equifax warned about vulnerability, didn't patch it: ex-CEO

Related Stories

Former Equifax chairman apologizes for data breach

October 2, 2017

The former chairman and CEO of Equifax says the company was entrusted with personal information of 140 million Americans and "we let them down" as human error and technology failures allowed a massive data breach.

Equifax says 100,000 Canadians' data hacked

September 19, 2017

The personal information of 100,000 Canadians may have been compromised in a hack of Equifax revealed earlier in the month, the credit data company said Tuesday.

US watchdog confirms probe of huge Equifax data breach

September 14, 2017

A US consumer protection watchdog agency said Thursday it has begun an investigation into a massive data breach at credit bureau Equifax that may have leaked sensitive information on 143 million people.

New Equifax CEO: Sorry for the hack and bad customer service

September 28, 2017

Equifax, under pressure from a massive data breach, is apologizing and trying again to make amends to consumers. Its new interim CEO—installed this week after the previous chief executive announced his retirement—offered ...

Recommended for you

What do you get when you cross an airplane with a submarine?

February 15, 2018

Researchers from North Carolina State University have developed the first unmanned, fixed-wing aircraft that is capable of traveling both through the air and under the water – transitioning repeatedly between sky and sea. ...

0 comments

Please sign in to add a comment. Registration is free, and takes less than a minute. Read more

Click here to reset your password.
Sign in to get notified via email when new comments are made.