Equifax Inc. is an American multinational consumer credit reporting agency headquartered in Atlanta, Georgia, and is one of the three largest consumer credit reporting agencies, along with Experian and TransUnion (together known as the "Big Three"). Equifax collects and aggregates information on more than 800 million individual consumers and more than 88 million businesses worldwide. In addition to credit and demographic data and services to business, Equifax sells credit monitoring and fraud prevention services directly to consumers.
Equifax operates or has investments in 24 countries in the Americas, Europe, and Asia Pacific. With more than 14,000 employees worldwide, Equifax has nearly US$5 billion in annual revenue and is traded on the New York Stock Exchange (NYSE) under the symbol EFX.
Contents
History
Equifax was founded as the Retail Credit Company by Cator and Guy Woolford in Atlanta, Georgia, in 1899. By 1920, the company had offices throughout the United States and Canada. By the 1960s, Retail Credit Company was one of the nation's largest credit bureaus, holding files on millions of American and Canadian citizens. Even though the company continued to do credit reporting, the majority of its business was making reports to insurance companies when people applied for new insurance policies, such as life, auto, fire and medical insurance. RCC also investigated insurance claims and made employment reports when people were seeking new jobs. Most of the credit work was then being done by a subsidiary, Retailers Commercial Agency.
Retail Credit Company's information holdings and willingness to sell its information attracted criticism in the 1960s and 1970s. These included that it collected "... facts, statistics, inaccuracies and rumors ... about virtually every phase of a person's life; his marital troubles, jobs, school history, childhood, sex life, and political activities." The company was also alleged to reward its employees for collecting derogatory information on consumers. This led to discrimination against queer people and people of color.
In 1970, after the company had computerized its records, which led to wider availability of the personal information it held, the U.S. Congress held hearings that led to the enactment of the Fair Credit Reporting Act. This legislation gave consumers rights regarding information stored about them in corporate databanks. It is alleged that the hearings prompted the Retail Credit Company to change its name to Equifax in 1975 to improve its image.
In expanding its business, Equifax acquired a number of companies in the health field. In May 1994, Equifax acquired HealthChex Inc., a company that specialized in profiling physicians and reviewing health insurance claims. In November 1994, it acquired Osborn Laboratories, a medical testing company. The same year, Equifax also acquired Electronic Tabulating Services, a clearinghouse for health insurance claims.
Equifax also expanded into commercial credit reports on companies in the United States, Canada and the UK, where it came into competition with companies such as Dun & Bradstreet and Experian. The insurance reporting was phased out. The company also had a division selling specialist credit information to the insurance industry but spun off this service, including the Comprehensive Loss Underwriting Exchange (CLUE) database as ChoicePoint in 1997. Equifax formerly offered digital certification services, which it sold to GeoTrust in September 2001. Also in 2001, Equifax spun off its payment services division, forming the publicly listed company Certegy, which subsequently acquired Fidelity National Information Services in 2006. Certegy effectively became a subsidiary of Fidelity National Financial as a result of this reverse acquisition merger (See Certegy and Fidelity National Information Services for further information).
Products
Equifax primarily operates in the business-to-business sector, selling consumer credit and insurance reports and related analytics to businesses in a range of industries. Business customers include retailers, insurance firms, healthcare providers, utilities, government agencies, as well as banks, credit unions, personal and specialty finance companies and other financial institutions. Equifax sells businesses credit reports, analytics, demographic data, and software. Credit reports provide detailed information on the personal credit and payment history of individuals, indicating how they have honored financial obligations such as paying bills or repaying a loan. Credit grantors use this information to decide what sort of products or services to offer their customers, and on what terms. Equifax also provides commercial credit reports containing financial and non-financial data on businesses of all sizes. Equifax collects and provides data through the National Consumer Telecom and Utilities Exchange (NCTUE), an exchange of non-credit data including consumer payment history on telecommunications and utility accounts.
In 1999, Equifax began offering services to the credit consumer sector in addition, such as credit fraud and identity theft prevention products. Equifax and other credit monitoring agencies are required by law to provide US residents with one free credit file disclosure every 12 months; the Annualcreditreport.com website incorporates data from U.S. Equifax credit records. Equifax also offers fraud prevention products based on device fingerprinting such as "FraudIQ Authenticate Device". Equifax also offers a credit protection service, called Equifax Protect.
Security failings
According to senator Michael Crapo, "The amount of data that the private industry and Government collect and store is very concerning. There is intrinsic vulnerability in collecting and storing personal financial information, and we need to have a meaningful discussion on how to protect and limit access to it."
2016 advance-warnings of insecure systems
According to an October 2017 report from Motherboard, around December 2016, a security researcher examining Equifax's servers found that an online portal, created for Equifax employees only, was accessible to the open Internet.
"I didn't have to do anything fancy," the researcher told Motherboard, explaining that the site was vulnerable to a basic "forced browsing" bug. The researcher requested anonymity out of professional concerns. "All you had to do was put in a search term and get millions of results, just instantly—in cleartext, through a web app," they said. In total, the researcher downloaded the data of hundreds of thousands of Americans in order to show Equifax the vulnerabilities within its systems. They said they could have downloaded the data of all of Equifax's customers in 10 minutes: "I've seen a lot of bad things, but not this bad."
The same types of sensitive private information of American consumers (names, birth dates, social security numbers, etc.) were exposed as in the May–July breach, according to Motherboard. Additionally, the security researchers said they were able to gain shell access on Equifax's servers and discovered and reported to Equifax additional vulnerabilities. According to the reporting, despite receiving this warning from the security researcher, the affected portal was not closed until six months later in June, well after the March and May–July breaches had begun. Moreover, the employee portal was reportedly not the same server targeted in the later breaches, which Motherboard speculates may suggest multiple breaches by more than one party may have occurred.
March 2017 security breach
On September 18, 2017, Bloomberg News reported that Equifax had been the victim of a "major breach of its computer systems" in March 2017, and that in early March it had begun "notifying a small number of outsiders and banking customers" about this attack.
According to Bloomberg, a person familiar with the breach believed this early-March intrusion may have been carried out by the same party that breached Equifax's computer systems again in May. According to Bloomberg, Equifax enlisted Mandiant (owned by FireEye, Inc.) to assist in investigating the March attack. The same cybersecurity firm was hired following the May–July breach.
May–July 2017 data breach
Between May and July 2017, currently unidentified hackers were able to use a known exploit on one of Equifax' web servers that had yet to be updated to access the credit records of more than 140 million Americans as well as some British and Canadian citizens before the breach was detected and shut down. Equifax disclosed the breach on September 7, 2017, after determining the means and scope of the breach. The event was considered "one of the biggest data breaches in history."
Several consumers filed lawsuits in small-claims court against Equifax due to the breach, while Equifax later came to a $575 million settlement with the Federal Trade Commission to offer either a cash payment or credit monitoring for those affected by the breach. The data from the breach has yet to be seen on black markets or the dark web by security experts, making it difficult to identify the origin of the breach. However, in February 2020, the United States Department of Justice indicted four members of China's People's Liberation Army on nine charges related to the breach, which China has denied.
2017 exposure of Argentine consumer data
In September 2017, Brian Krebs revealed that the Argentine arm of Equifax had left private data from approximately 14,000 consumers, and more than 100 staff members, available to anyone who entered "admin" as both the username and password for one of its online systems.
2017 withdrawal of vulnerable mobile apps
On September 7, 2017, the same day as Equifax announced a large security breach, Equifax removed its official mobile apps from the Apple App Store and from Google Play. While these apps themselves were not reportedly connected to that breach, they had security flaws of their own, being vulnerable to man-in-the-middle attacks owing to some parts using HTTP instead of HTTPS.
2017 exposure of American salary data
On October 8, 2017, Krebs reported that The Work Number, a website operated by Equifax's TALX division, exposed the salary histories for employees of tens of thousands of US companies to anyone in possession of the employee's Social Security Number and date of birth. For roughly half the US population, both of the latter pieces of data are known to be in possession of criminals, following Equifax's May–July 2017 security breach. In July 2019, Equifax settled with the Federal Trade Commission for $700 million. This number contains a $380,500,000 consumer restitution fund, part of the class action lawsuit.
Website malware
On October 12, 2017, Equifax's website was reported to have been offering visitors malware via drive-by download. The malware was disguised as an update for Adobe Flash. At that time, only 3 out of 65 top anti-malware products provided protection against the particular malware, meaning that many visitors were at risk of having their computers infected when visiting the Equifax website. On October 13, 2017, the attack was revealed to have been performed by hijacking third-party analytics JavaScript from Digital River brand FireClick. Also on October 13, 2017, the U.S. Internal Revenue Service was reported to have suspended a $7.2 million contract with Equifax as a result of the attack.
Criticism
In 1982, Retail Credit Company was criticized for collecting "...facts, statistics, inaccuracies and rumors... about virtually every phase of a person's life; his marital troubles, jobs, school history, childhood, sex life, and political activities."
The company was charged with rewarding its employees for collecting negative information on consumers in the 1970s. There was a consent decree. In 1975 the company changed its name to "Equifax"—reportedly to counteract its tarnished reputation.
Lawsuits and fines
The company has been fined by the Federal Trade Commission on two occasions for violating the Fair Credit Reporting Act ("FCRA"). In 2000, Equifax, along with Experian and TransUnion, was fined $2.5 million for blocking and delaying phone calls from consumers trying to get information about their credit. In 2003, the FTC took Equifax to court for the same reason and settled its lawsuit with the company for a fine of $250,000.
In July 2013, a federal jury in Oregon awarded $18.6 million to Julie Miller of Marion County against Equifax for violations of the Fair Credit Reporting Act. In her lawsuit, Miller alleged Equifax had merged her credit reports with another person with a different Social Security number, date of birth, and address. Miller contacted Equifax repeatedly in writing and over the telephone, but Equifax refused to delete dozens of false collection accounts from Miller's credit report. The award included $18.4 million in punitive damages, and $180,000 in compensatory damages. Miller's lawyer, Justin Baxter, explained that the false reporting damaged Miller's reputation, she was denied credit, and her private information was given to businesses Miller had no relationship with. The jury's verdict is believed to be the largest award in an individual case under the Fair Credit Reporting Act. An Equifax spokesperson said that Equifax is considering appealing the jury's verdict. A federal judge reduced the award to $1.62 million in 2014.
In 2014, Equifax and Heartland Bank were sued by Kimberly Haman of the St. Louis area for reporting she was dead. A Heartland Bank spokesperson said the bank "immediately investigated and contacted the credit reporting agencies after Haman reported" she was still alive. An Equifax "spokesperson told the Post-Dispatch that Equifax blocked the Heartland account information from appearing on Haman's credit report after a reporter's inquiry." In April 2014, Equifax was sued in New York federal court by God Gazarov, who claimed the company erroneously reports him as having no credit history because of his unusual first name. Gazarov settled his lawsuit in May 2015, with Equifax agreeing to enter his name into their database.
On November 4, 2017, it was reported that a group of five Oklahomans had sued the company, claiming that Equifax "violated laws which require financial institutions to protect the security of their customers' personal information." Equifax selected the law firm DLA Piper to work on the case in D.C. It had turned to Edelman for earlier crisis control after the October 2017 privacy breach. Consumer lawsuits claiming damages under the FCRA have been successful in small claims court. Equifax software engineer Sudhakar Reddy was charged with insider trading for purchasing options prior to the disclosure of the 2017 data breach.
