Equifax Is Said to Be Near $650M Settlement for Data Breach
nytimes.com
nytimes.com
I think I got them to spend more than I would have received in any settlement.
Fun note, my judge in small claims dismissed my case but said the following before dismissing it, "Mr. tuxxy, I would not trust Equifax with my dog's vaccination records. I'm absolutely appalled in the lack of protections Equifax provides for the personal data of Americans, however I'm afraid I don't see a case for negligence..."
She lectured Equifax's lawyers a bit on what a shitty offer credit monitoring was for the loss of my PII for a bit, then sent us out.
I trolled their legal team a bit near the end and tried to settle for $3.50 after mediation failed, but I wanted them to refer to the $3.50 as "tree-fiddy" in the settlement, but they refused. Oh well...
I wish more people took them to court. It was not difficult to do and is quite an effective form of direct action because they have to spend quite a bit of money to fight it.
https://www.troyhunt.com/authentication-and-the-have-i-been-...
"In choosing the $3.50 figure, I wanted to ensure it was a number that was inconsequential to a legitimate user of the service. That's about what a latte costs at my local coffee shop so spending a few bucks a month to search through billions of records seems like a pretty damn good deal, especially when that rate limit enables 57.6k requests per day."
Unless they just steal a credit card. Not unlikely, given who we're talking about here.
Using an "exhausted" stolen card would get flagged by a good payment provider (Stripe!)
The only issue is in some parts of this world credit cards are difficult to obtain.
However, are you afraid they may come after you for some kind of revenge?
Moreover, their DLP system was offline for the period of hack due to certificate expiration.
IANAL, but there was a clear case of negligence.
-- ed:
There were winning cases against equifax. the payout was awarded for the damages - 3 years of credit counceling and monitoring, something in $6k range.
Can someone more educated in how these fines work teach me about how these numbers are calculated?
The ratio of market cap differences is about 34:1. If Facebook's fine is adjusted to Equifax's it would be a $22.1B fine instead of $5B.
So, from a market cap perspective Equifax's fine is ~4x Facebook's.
If you cause $100 in damages, you pay $100 (plus any punitive awards). Doesn't matter what your shares happen to be trading at that day.
It seems less scofflaw companies aren't offered the chance to serve the same markets because criminal companies are let off too lightly.
A fine is meant to deter as well as punish. If the fine is too small, it won't deter. And certainly if less than the profits earned, it can't punish, nor deter.
Losing $650 million is perhaps not quite as compelling a story as losing billions, or a smoking hole where a company used to be (as in Enron and Arthur Andersen). But it's a pretty big chunk of change. I have no experience making such arguments, but it seems plausible that it will be remembered for a while at Equifax and their competitors, at least?
I'm doubtful that people respond to such incentives rationally. It probably has more to do with how well the storyteller tells the story. And whether the thing they're selling actually works well for improving security seems pretty hit-and-miss, too.
Primarily, I want my justice system to administer justice.
Which doesn't make any sense and just gives them the incentive to play the same games they do in avoiding taxes.
The first reason it doesn't make sense is that the penalty should have some relation to the damages. If you cause $500 damage to someone else without their consent, screw you. But if the fine for that is $5000 per victim, it's a deterrent no matter how big you are, because $5000 is more than $500 (and provides a fair margin for the probability of not getting caught), and if the company is getting more than $500 in value from doing it then it could have just offered to pay the victim $501 to consent to allowing it, which implies that they're not.
Meanwhile if you don't think large corporations can move numbers around on a spreadsheet to minimize what they owe, you haven't been paying attention. And we sure as heck don't need a system where Equifax gets to put its risky business in one entity that has inconsequential revenues and then suffer a $10 total fine when it screws up this bad because whatever penalty percentage of almost nothing rounds to zero.
As I've said elsewhere, I'm not advocating one particular method of coming up with this number. I'm just saying that the fine should depend on the company, not be a flat number based on damages caused.
If you don't do it this way, you end up in a situation similar to speeding tickets: well-off people don't care at all (and are even probably more annoyed about having their drive interrupted than the actual fine), but it can mean a poor person has to skip meals to recover. If the goal is discouraging a certain type of behavior overall, it has to hurt violators comparably, no matter their wealth.
I would believe that if these companies didn't just keep doing what they were doing anyway. Losing a percentage of revenue or profit for one year does nothing to deter them! We need to reinstate the corporate death penalty. Equifax deserves to die for its negligence, IMO.
The only way things will change is if the fines hurt more, but it needs to hurt the huge companies just as much as the small ones, otherwise it ends up just being another factor that helps keep the already-dominant companies at the top.
Facebook's stock went up because they had a pending fine, and the value of the fine was announced, reducing uncertainty. Put another way, would you buy a car that has an unknown repair bill for the same price as a car you know how much it's going to cost to fix?
The prudent man rule which requires senior executives to take personal responsibility for ensuring the due care that ordinary, prudent individuals would exercise in the same situation. This rule, developed in the realm of fiscal responsibility, now applies to information security as well.
The intent was to patch the system but they experienced some sort of issue that prevented the timely action. From what I understand, you only have to show the courts that we tried to do the right thing and had the right intention.
Plus they aren't involved in any election scandals which certainly helps....
The one positive thing that came out of all this is that you can lock down your credit for free and open it again for free when you need to . Basically no one could ever open an account or credit card in your name if the offering party tries to run a credit report.
Yes, plus their perceived censoring of right-leaning content (real or imagined).
But between the election stuff and their attempt to setup a currency whose monetary policy would be governed by a group of wealthy corps and partly based in another country regulated by a foreign body... these are things that touch on the sovereignty of the US, and no government wants internal competition on that front.
Facebook breached a consent decree with the FTC [1]. Demonstrating harm was simple—they breached a settlement.
Equifax’s harm is potentially great. But demonstrating damages is difficult.
TL; DR Facebook is a repeat offender.
[1] https://www.ftc.gov/news-events/press-releases/2011/11/faceb...
I still don't see how less than $5 per person who's data was compromised constitutes a reasonable settlement.
That's what's frustrating about most of Elon's crap. Don't test the patience of the SEC with _tweeting_. Put your phone away and save that social capital for when you actually need it.
FB is more strategic but still repeatedly misleads congress, the FCC, etc. After a while, they're sick of being made to look a fool. Notice that FB isn't getting the "trust us" benefit of the doubt with Libra (nor should they.)
That being said, it's important to understand that in the US, penalties are assessed based on the seriousness of the infraction, not on the ability of the perpetrator to pay.
And while it might be the opinion of lots of HN commenters that the equifax breach caused "incalculable" harms, demonstrating this level of harm in court would be tremendously difficult.
It's not about ability, it's about whether the fine is a suitable punishment and deterrent.
When the penalty is less than $5 per person affected, how am I expected to take that seriously? A penalty based on the actual seriousness of the infraction would put the company out of business, and that's what should have happened.
% of revenue doesn’t work because some companies are high-revenue low-profit (supermarkets), others are low-revenue high-profit (luxury goods). % of profit doesn’t work because profit is fairly arbitrary (if a company reinvests everything, then zero profits). Cash on hand is even more arbitrary.
But % of market cap tells us exactly the impact on owners, it’s literally the amount their stock is going down and they’re therefore being penalized.
That stuff has to be worth more than $4.5.
With GDPR now in place here in the UK you can write to an organisation and ask them to delete all your data.
It would appear Equifax is above this new law...
> Please note that given the importance of complete and accurate credit records, for purposes including for responsible lending, it will usually be appropriate to continue processing credit report data -in particular, to protect the rights of another natural or legal person, or because it’s an important public interest of the union or member state.
Equifax goes out and gathers your personal finance data without even asking, they literally take it whether you want them to or not.
Facebook is data people choose to share freely.
This just seems like equifax should be settling with an extra zero on the end!
4,48$ per person.
That ought to undo the damage of all your most personal information being public.
The damages should completely wipe out all existing shareholders, and the company should be unable to continue as a going concern.
Do you own any stock in a S&P 500 index fund, such as VFINX / VFIAX, SWPPX, FXAIX, PREIX, etc? Congratulations, you're a shareholder.
Government doesn't want to be the force that creates a monopoly of the remaining two companies.
Government also doesn't want a corporation desperate enough to put the government in front of a judge and jury.
So the result is kickback and relax. Emphasis on kickback.