Consumers who sought cash settlement from Equifax probably won't get full $125
cnbc.com
cnbc.com
I’m not pumped that Equifax is getting off for less than a half billion or that the attorneys are getting a big chunk of that. (It’s hard to say how much they should get, to be honest) But when I see a bullshit headline I have to call it out.
By the way, they based the $125 on the assumption that almost everyone would take the worthless credit monitoring option.
The 77.5 is roughly 20% of the settlement fund
Or if you want to include the crap credit monitoring it is 11% of the total 700
In either case no one will be getting near 125 but still 80 million is quite a lot for them...
Against $3.5bln in 2019 revenues? That's not really a lot at all.
If the two sides negotiated a settlement that involved a serious change of business practices at Equifax, a significant payout to meaningfully compensate victims, and a chocolate cake for every retired librarian in Tallahassee, I'd be slightly confused but I would be unequivocally happier with that settlement than the current one. While you could probably save a bit of money on the chocolate cakes, it would be much smaller than any of the other amounts in the case, and saving that money wouldn't have any real impact on the settlement actually doing what it needed to do.
It's not like there was some busy public defender that didn't have time to think "gee, these people deserve more than a couple bucks and the company is probably going to make money off this 'fine' once the yearly renewal kicks in for those that opted for the coverage how can we argue a stronger deal" there was a high end team that made bank on a deal they knew they were the only ones making real money on regardless of what the deal was.
I'll be honest, as a victim, I'm not sure what I'm supposed to do with $125, either. I expect most people will spend it on themselves, but even spending it on credit monitoring doesn't actually fix the problem, it just makes the problem a little less bad, maybe, at the cost of enriching other companies that depend on this ecosystem of profiting off other people's data. I would genuinely prefer a settlement that cost Equifax $800M and got me nothing to one that cost $80M and got me $125.
If the lawyers had instead negotiated a settlement that got them fees of $800 million, then, because as you say the fees come out of the settlement amount, the settlement would have to be at least $800 million. That would be good for me, as a victim, because it would have meant a larger penalty to Equifax.
" Net income attributable to Equifax of $299.8 million was down 49 percent compared to the full year 2017. " https://www.prnewswire.com/news-releases/equifax-releases-fo...
Apparently the CEO got $20 million in salary.
Edit: The more relevant number is the $6 million the CTO got!
Man I suck: At least the Chief Information Security Officer got less than $4 million.
Equifax should pay damages related to the severity of the breach not to the size of their bank account.
It’s like Apple’s MacBooks blowing up and a judge ruling Apple can give iCloud storage as compensation.
Which also lets them spam all their old customers who do not otherwise receive promotional emails from them.
Here’s EPIC’s summary of the legislation options: https://www.epic.org/GradingOnACurve/
Equifax: YOU NEED THIS PROTECTION. PAY US... or else maybe there will be an ACCIDENT with your data
Me: No, I don't, think so. Shit, sounds illegal to me
Equifax: WHOOPS. We had an accident.
Me: WTF? [calls authorities]
Equifax: Well, let us make this right, how about we now give you some _free_ protection as a sign of our goodwill... you know to try it out... just in case that WHOOPS ends up being a problem for you.
Me: [looks at response from authorities] This is okay? This is fucked.
This is state-sanctioned organized crime at its finest.
Because the time needed to fill out that form and provide the documents will have been worth more than the payout, if one ever comes, for just about anyone who bothered to do it.
Not at all satisfactory.
And no, it wouldn't be better to let them off the hook completely. I'm not saying this settlement is _at all_ satisfying, but c'mon.
It's a mess now. The gist of my original comment was "I agree with you".
¯\_(ツ)_/¯
https://www.baynews9.com/fl/tampa/news/2019/07/26/what-happe...
>Any funds unclaimed after 4-year extension will be distributed in services
>Services offered are for identity restoration, credit monitoring
And those services are from... Equifax, which I feel is pretty shitty. Like I said, I don't like the settlement itself, but lawyers get a lot of hate for class actions from people who seemingly don't appreciate the risk they take in taking in the case.
And who gave them the right to profit massively off the violation of my privacy. I should be able to sue them. This is not justice, this is profiteering off others misfortune.
This company should be "old yellered"
All class actions are this way.
The only correct move is to exclude yourself from the class and reserve your right to sue individually, after the class action, citing that as precedent.
Class members never get more than a useless coupon or comparable.
It would have been the greatest thing ever. This dumb ass bullshit system of credit reporting would have dissolved overnight. Instead we're stuck with the worst of all worlds. Our information is completely fucked, and we're the ones expected to protect it. And we're not even permitted to have proper tools to protect ourselves.
Risk assessment is a valid concern for lenders. Diligent payers should be rewarded.
Though I do think it would have hurt the bottom line of the giants that have few incentives to innovate, and many incentives to maintain the way things are.
A lot of systems that leverage data behind walled gardens, collected from the masses and for the benefit of the few could also have the same approach. A couple of high profile "leaks" come to mind…
All part of the push to make class-action lawsuits economically unviable. When it's not worth it for any lawyer, the corporations will be free to defraud everyone for small amounts.
Yes, the attorneys are taking 20% of the resolution. The resolution is so tiny that 20% of tiny is also tiny. The article title is highly misleading.
Look, I'll badmouth lawyers as much as the next person, but anyone who wants to claim class actions are a mistake needs to come up with a better system before they trash this one. There are so few avenues for consumers to hold companies accountable right now. They just don't exist. And thanks to arbitration and class action bans in EULAs, even the few avenues we do have are getting gradually eroded.
So first make regulatory penalties stricter, first set up real consequences for CEOs and boards. Then we can talk about revising class actions. I'm not satisfied with someone saying, "theoretically this could be better." Make the alternative systems better first, and then we'll talk about throwing away what we currently have. Like, holy crap, how short sighted can CNBC be? There are no working alternatives in the US to class actions right now.
The tragedy isn't that the lawyers took 20% of 380 million dollars. The tragedy is that it was only 380 million dollars. I'd happily trade another 25-50% on top of the current lawyer take if they had gotten that total up to 750 million, or even a billion.
If the courts deem that the resulting costs to the defendant are too low, additional amounts may be levied and given to relevant charities, or the ACLU (or things like it).
If the company would collapse due to the costs, or otherwise would be unable to pay the full costs, executive bonuses (and potentially some pay, with limits) may be reclaimed, both towards allowing payment, and preventing failure in "too big to fail" situations.
I miss anything?
People get restitution. Lawyers get rewarded for quality work. Companies both pay damages, and a penalty on top of damages. Executives bear responsibility as people, not just the corporate entity.
The request I would make is, "can we build a real, working version of the system you propose before we get rid of the existing one?" I'm not eager to throw away what we have on the promise that we could build something great afterwards.
The annoyance I feel when I read articles like this is that it's a bunch of reporters saying, "we need to do something about lawyers", and I just feel like -- if I'm in a leaky lifeboat, don't tell me to jump out of it until you have another boat next to me that I can climb into. We all know the lifeboat has leaks, but this lifeboat is real, and yours is (at least for now) imaginary.
https://money.cnn.com/2017/09/08/investing/equifax-stock-ins...
> Three Equifax executives sold shares of the credit-reporting company worth nearly $2 million shortly after a massive data breach was discovered.
However, I think a journalist is seriously delinquent if they don't acknowledge that insiders normally schedule their stock trades ahead of time to insulate from insider trading accusations. A reader needs to know whether this was the case or not in order to be appropriately outraged.
> I think a journalist is seriously delinquent if they don't acknowledge ...
I'm not sure I agree. If you consider how many topics journalists write about and how much necessary context that they would have to background-boilerplate, a 2 sentence update could easily become the length and readability of a ToS contract.
This isn't like, one article with a unique context. There have been lots of similar ones and will continue to be.
"Insider trading creates perverse incentives" would not inherently mean that the purported insider trading by equifax executives was a bad thing.
Otherwise it’s too hard to prove you didn’t act on insider info since they see such info every day.
From a tech perspective I feel like issues like this should have a public canonical ID. That would help regulators and reporters alike deliver information in a more clear, cost effective and accountable manner, disambiguation by default. Interested and affected parties could subscribe to updates on that key across the web.
In addition to the SEC litigation into the executives, Equifax did a company-wide investigation and found that one of the developers for that breach notification website (the one that provided tons of false positive and false negatives and was spoofed by a security researcher) traded using his SO's equities trading account before the breach was revealed. The company found him and he has also been prosecuted[2].
[1] https://www.sec.gov/news/press-release/2018-115
[2] https://www.zdnet.com/article/equifax-engineer-who-designed-...
If I worked at Amazon and saw Jeff Bezos in a meeting room going ballistic on the lead security engineer, would I be insider trading if I shorted amazon stock?
Yes, for sure. You'd still be acting on non-public information (the fact that he went ballistic on the head of security).
If you leaked that meeting to the press first, then maybe you'd be in the clear on insider trading (but you'd be in deep water for the leak!).
https://www.cfainstitute.org/ethics/codes/std-of-practice-gu...
If it cost them as much to clean up each spill as it cost BP, you better believe they would take better care not to let it happen again.
It's so sad that this is even remotely controversial. Equifax should have gotten the same treatment as Arthur Andersen.
From my rational, informed side, I would argue no. Here's my rationale.
The data stolen from Equifax has not shown up on the black market and hasn't been actively used, which suggests this was a nation-state using the data for something other than profiting from fraud. This also suggests that the hack could easily be considered an "act of war", so given enough time+effort+resources, no company would likely be able to resist that breach (although I know Equifax could have done FAR better than they did).
Technically I don't "own" the data that Equifax has about me. Equifax owns the collection of it, their reporters (ex retailers, landlords, bank/mortgage companies) each own a shard, and other data aggregators who contract with any one of these actors can own part/all of it.
I am not Equifax's customer. They are required to deal with me based on a few rules defined in the Fair Credit Reporting Act, but the FCRA also provides some protections for credit reporting agencies who don't violate those rules. I'm sure they minimize the effort/resources they devote to helping credit consumers because that is the profit motive of every company.
I'm sure Equifax has a ridiculous EULA/ToS that I probably implicitly agreed to when I used the AnnualCreditReport website, and probably additionally when I deal with any retailer that pulled credit reports from Equifax (including the IRS after the breach was revealed). It likely involved me signing away my rights to a class action litigation or my rights to a trial by jury, because that is par for large contemporary corporations.
The standard for "protecting consumer data" is remarkably low except in a few sectors (ex. healthcare, retailers storing credit card data), and even in those it's still disheartening. The problem here is that companies can easily argue to {regulators, judges/juries, their BoD, cybersecurity vendors} that they can't be expected to spend more than the industry average because that hurts them more than the competitors. This just becomes a Prisoner's Dilemma where our data's security becomes the victim to corporate (in this case credit reporting bureau) self-interested decision making.
Yet - and also the absence of evidence doesn't mean the evidence of absence. Not all criminals are stupid, a smart one would wait till vigilance dies down.
> Technically I don't "own" the data that Equifax has about me.
This itself is a big part of the problem. It should absolutely be illegal for companies to hold sensitive info like my SS# without my permission.
I think the USA needs stronger regulators who can actually enforce the laws using fines and lawsuits rather than the legal system which does not work.
The eventual endgame of this system would be that law firms’ costs should rise to eat as much of the settlement as possible, which leaves as little as possible for the actual victims.
A fixed percentage system creates an incentive to maximize the settlement (on behalf of the victims) and leaves the law firm to pay its own costs.
I went to their website trying to figure out how to lock my credit report (which US govt mandated be a free thing to do) only to learn that in order to use the "free" option you have to go through hours of phone trees, or write in snail mail.
If you want the ability to lock the report online or via an app, you have to pay ~$20/mo to Equifax. Total BS, and of course I wouldn't put it past this company to make money off their own data leak.
> In fact, consumers were never going to get $125, ... “That’s down to $6 or $7 [per consumer] now. Maybe even less than that,”
That's what all your personal information and your identity is worth. $6.
That's not how much it's worth, that's just how much Equifax was able to corruptly negotiate to pay for losing it.
If you really want to know how much it's worth, you could probably compute a reasonable estimate by taking all the money the credit bureaus from your credit file, and divide that by the number of credit files.
Also, when that statement is ever made, it really highlights flaws in our system when the rich/corporations/layers write the laws in their favor... So much for "for the people" right?
I have no idea how much the company made by charging transaction fees on credit card payments for student loans (that's what they're accused of) but they got off with a slap on the wrist. They should have been required to give back ALL the money they made. Fucking scammers.
I can't parse this, how can a $380m fund be capped at $31m, isn't that a $31m fund?
Conjecture is it was a nation state.
In practice, as usual, they're getting fined $5 for stealing $100, so not really.