Equifax to Pay New York $19.1 Million as Part of Settlement Over Data Breach
State officials in New York announced their part in the global settlement Monday after court papers were filed on the agreement in Atlanta.
July 22, 2019 at 10:38 AM
6 minute read
Equifax has agreed to pay $19.1 million in fines to New York state officials as part of a broader $1.4 billion settlement to resolve what's been considered one of the largest digital breaches of personal data in history.
State officials in New York announced their part in the global settlement Monday after court papers were filed on the agreement in Atlanta.
Equifax has agreed to pay a fine of $10 million to the New York State Department of Financial Services as part of the settlement. An additional $9.1 million was secured by the New York Attorney General's Office as part of a multistate investigation into the company.
That's separate from the $425 million in restitution that Equifax has agreed to pay after the personal information of more than 147 million consumers was exposed and illegally accessed in September 2017. That was more than half of the adults living in the U.S.
New York Attorney General Letitia James said in a statement Monday that Equifax had been negligent in protecting the personal data of consumers.
“Equifax put profits over privacy and greed over people, and must be held accountable to the millions of people they put at risk,” James said. “This company's ineptitude, negligence, and lax security standards endangered the identities of half the U.S. population.”
The multistate investigation found, specifically, that attackers targeted vulnerabilities in the company's Apache Struts software, which is used to develop web applications. Equifax was told about the potential for a breach earlier in 2017, the investigation found, but didn't take the necessary steps to correct the problem.
The attackers then used the vulnerability to access the personal information of millions of consumers, a breach that went unnoticed by Equifax for more than two months.
Equifax had agreed to pay for a Consumer Restitution Fund of up to $425 million as part of the settlement. It'll start with an immediate commitment of $300 million, which will be followed by an additional $125 million if those funds run out.
Under the accord, the company will pay another $175 million to the 48 states involved in the lawsuit, Washington, D.C., and Puerto Rico. New York will receive $9.1 million of those funds as a result of the probe.
A second investigation, led by the New York State Department of Financial Services, will net New York $10 million after the agency found Equifax had separately violated state and federal financial laws.
DFS Superintendent Linda Lacewell said the settlement announced Monday reinforces the agency's commitment to protecting consumers when it comes to financial institutions and digital threats.
“First and foremost, the settlement announced today holds Equifax accountable for its egregious breach in its duty to consumers in safeguarding their sensitive personal identifying information and restores some peace of mind and protection to New Yorkers,” Lacewell said. “Strengthening consumer protections for New Yorkers, DFS now requires credit rating agencies to be licensed and supervised by DFS, and comply with the Department's landmark cybersecurity regulation to better guard against potential breaches.”
The agency's investigation focused on the security practices of Equifax, both during and at the time of the breach, and its communications with consumers following the event. DFS concluded that the company's practices violated the federal Dodd-Frank Act and state Financial Services Law, §208.
The breach itself, the agency found, had the potential to seriously harm consumers through the exposure of their personal information, such as Social Security numbers, credit card information, and more. After the breach was announced, the company didn't do enough to inform and guide consumers whose data may have been compromised, the agency said.
The federal counterpart of DFS, the Consumer Financial Protection Bureau, will receive an additional $100 million from Equifax as part of the settlement.
Mark Begor, the CEO of Equifax, called the settlement a “positive step” in a statement Monday morning. He said the company has committed more than $1 billion to a technology and security investment program to provide further protections for consumers.
“This comprehensive settlement is a positive step for U.S. consumers and Equifax as we move forward from the 2017 cybersecurity incident and focus on our transformation investments in technology and security as a leading data, analytics, and technology company,” Begor said. “The consumer fund of up to $425 million that we are announcing today reinforces our commitment to putting consumers first and safeguarding their data — and reflects the seriousness with which we take this matter.”
Consumers who were affected by the breach, of which there were many, will be required to submit claims showing they were a victim of fraud or took proactive steps to set up credit-monitoring services by submitting documents online or by mail.
Equifax has also agreed to offer consumers up to 10 years of free credit-monitoring services if they were one of the millions whose data was exposed. That will include up to $1 million of identity theft insurance, with no deductible. The first four years will include credit monitoring by the country's three largest agencies, while the remainder will only be from Equifax.
A new website to assist consumers in submitting a claim, enrolling in credit-monitoring services, or just learning more will be set up sometime in the near future, according to state officials. Consumers can visit the Federal Trade Commission's website in the meantime for more information.
Consumers affected by the breach won't be able to immediately submit a claim after Monday's announcement. The settlement ultimately will require court approval, according to state officials.
READ MORE:
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllBen & Jerry’s Accuses Corporate Parent of ‘Silencing’ Support for Palestinian Rights
3 minute readTrending Stories
- 1Elon Musk Names Microsoft, Calif. AG to Amended OpenAI Suit
- 2Trump’s Plan to Purge Democracy
- 3Baltimore City Govt., After Winning Opioid Jury Trial, Preparing to Demand an Additional $11B for Abatement Costs
- 4X Joins Legal Attack on California's New Deepfakes Law
- 5Monsanto Wins Latest Philadelphia Roundup Trial
Who Got The Work
Michael G. Bongiorno, Andrew Scott Dulberg and Elizabeth E. Driscoll from Wilmer Cutler Pickering Hale and Dorr have stepped in to represent Symbotic Inc., an A.I.-enabled technology platform that focuses on increasing supply chain efficiency, and other defendants in a pending shareholder derivative lawsuit. The case, filed Oct. 2 in Massachusetts District Court by the Brown Law Firm on behalf of Stephen Austen, accuses certain officers and directors of misleading investors in regard to Symbotic's potential for margin growth by failing to disclose that the company was not equipped to timely deploy its systems or manage expenses through project delays. The case, assigned to U.S. District Judge Nathaniel M. Gorton, is 1:24-cv-12522, Austen v. Cohen et al.
Who Got The Work
Edmund Polubinski and Marie Killmond of Davis Polk & Wardwell have entered appearances for data platform software development company MongoDB and other defendants in a pending shareholder derivative lawsuit. The action, filed Oct. 7 in New York Southern District Court by the Brown Law Firm, accuses the company's directors and/or officers of falsely expressing confidence in the company’s restructuring of its sales incentive plan and downplaying the severity of decreases in its upfront commitments. The case is 1:24-cv-07594, Roy v. Ittycheria et al.
Who Got The Work
Amy O. Bruchs and Kurt F. Ellison of Michael Best & Friedrich have entered appearances for Epic Systems Corp. in a pending employment discrimination lawsuit. The suit was filed Sept. 7 in Wisconsin Western District Court by Levine Eisberner LLC and Siri & Glimstad on behalf of a project manager who claims that he was wrongfully terminated after applying for a religious exemption to the defendant's COVID-19 vaccine mandate. The case, assigned to U.S. Magistrate Judge Anita Marie Boor, is 3:24-cv-00630, Secker, Nathan v. Epic Systems Corporation.
Who Got The Work
David X. Sullivan, Thomas J. Finn and Gregory A. Hall from McCarter & English have entered appearances for Sunrun Installation Services in a pending civil rights lawsuit. The complaint was filed Sept. 4 in Connecticut District Court by attorney Robert M. Berke on behalf of former employee George Edward Steins, who was arrested and charged with employing an unregistered home improvement salesperson. The complaint alleges that had Sunrun informed the Connecticut Department of Consumer Protection that the plaintiff's employment had ended in 2017 and that he no longer held Sunrun's home improvement contractor license, he would not have been hit with charges, which were dismissed in May 2024. The case, assigned to U.S. District Judge Jeffrey A. Meyer, is 3:24-cv-01423, Steins v. Sunrun, Inc. et al.
Who Got The Work
Greenberg Traurig shareholder Joshua L. Raskin has entered an appearance for boohoo.com UK Ltd. in a pending patent infringement lawsuit. The suit, filed Sept. 3 in Texas Eastern District Court by Rozier Hardt McDonough on behalf of Alto Dynamics, asserts five patents related to an online shopping platform. The case, assigned to U.S. District Judge Rodney Gilstrap, is 2:24-cv-00719, Alto Dynamics, LLC v. boohoo.com UK Limited.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250