Equifax fined £11m for data breach

The UK’s Financial Conduct Authority (FCA) has fined credit reporting agency Equifax £11,164,400 for failing to manage and monitor the security of UK consumer data it had outsourced to its parent company based in the US. 

The regulator says the breach allowed hackers to access the personal data of millions of people and exposed UK consumers to the risk of financial crime. 

In 2017, Equifax’s parent company, Equifax Inc, was subject to one of the largest cybersecurity breaches in history. Cyber-hackers were able to access the personal data of approximately 13.8 million UK consumers because Equifax outsourced data to Equifax Inc’s servers in the US for processing.

The UK consumer data accessed by the hackers ranged from names, dates of birth, phone numbers, Equifax membership login details, partially exposed credit card details and residential addresses.

The FCA says the cyberattack and unauthorised access to data was “entirely preventable.” Equifax did not treat its relationship with its parent company as outsourcing and as a result, it failed to provide sufficient oversight of how data it was sending was properly managed and protected. There were known weaknesses in Equifax Inc’s data security systems and Equifax failed to take appropriate action in response to protect UK customer data, says the FCA. 

Equifax did not find out that UK consumer data had been accessed until six weeks after Equifax Inc had discovered the hack. The firm was informed about the incident approximately five minutes before it was announced by the US parent company. This meant Equifax was unable to cope with complaints it received when the incident was announced and led to delays in contacting UK customers.

Following the cybersecurity breach, Equifax made several public statements on the impact of the incident to UK consumers which the FCA says gave an inaccurate impression of the number of consumers affected. Equifax is also accused of treating consumers unfairly by failing to maintain quality assurance checks for complaints following the cybersecurity incident, meaning complaints were mishandled.

Regulated financial firms are required to have effective cyber security arrangements to protect the personal data they hold. Firms must keep systems and software up to date and fully patched to prevent unauthorised access and remain responsible for data they outsource.

When an FCA-authorised firm becomes aware of a data breach, it is essential it promptly notifies affected individuals in a way which is fair, clear and not misleading and implements fair complaints handling procedures.

Jessica Rusu, the FCA’s Chief Data, Information and Intelligence Officer, said: “Cyber security and data protection are of growing importance to the security and stability of financial services. Firms not only have a technical responsibility to ensure resiliency, but also an ethical responsibility in the processing of consumer information. The Consumer Duty makes it clear that firms must raise their standards.”

Facebook
Twitter
LinkedIn