Attacks/Breaches
9/11/2017
06:30 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Equifax Gets Slammed, Removes Forced Arbitration Clause from Credit Monitoring Offer

Company's initial requirement that breach victims sign away their legal rights to get complimentary offer was one of several mistakes.

Equifax Monday announced changes to its free credit-monitoring offer for victims of the massive data breach it disclosed last week, after getting slammed for originally attempting to force people to sign over their rights to legal recourse in order to enroll.

In a breach update, Equifax said it has removed certain language from the Terms of Use on the third-party website victims have to use to sign up for the credit monitoring service. It has also added a FAQ to its own website to confirm that enrolling in the complimentary credit monitoring offer does not waive any rights to take legal action against the company.

Earlier, consumer advocacy groups such as Public Citizen, New York Attorney General Eric Schneiderman, the Consumer Financial Protection Bureau, and Sen. Sherrod Brown (D-Ohio) were among many who had demanded that Equifax remove the forced arbitration clause in its original credit monitoring offer. The clause basically prohibited people who signed up for the offer from later suing the company in court.

"The wounds were totally self-inflicted," says Bob Ackerman, a managing director at cybersecurity venture firm Allegis Capital. "The debacle of perceived release of liability, if you opted in to their credit-watch services was just pure stupidity."

In addition to acquiescing to the demand to remove the clause, Equifax said it would also not require a consumers' credit card information when they sign up for the offer. Neither will consumers be automatically enrolled or charged at the end of the free period, the company said. There had been some concern over both requirements when Equifax originally announced the complimentary credit-monitoring offer — particularly over the prospect that the company could actually end up making money over the breach.

"We are listening to issues consumers have experienced and their suggestions. These are helping to further inform our actions," the company noted in Monday's update.

Equifax's moves to soothe frayed tempers, while some might see as a positive development, is unlikely to do much to mitigate the fallout from the breach.

In the four days since Equifax announced the breach, the company's shares have fallen by over 20%, erasing billions of dollars in market value in the process. From around $142.70 last Thursday, Equifax's share price had tumbled to around $111.30 about 90 minutes before market close Monday. Some financial experts expect prices will fall even further to around $100 by mid-October.

Schneiderman, and attorneys general from Connecticut, Illinois, Pennsylvania, Massachusetts, and other states already have launched investigations or have announced their intention to do so soon.

It is almost a sure bet that Equifax will need to respond to similar investigations from every single state AG. Among the issues they will probe is the 40-day delay between when Equifax first discovered the breach and when it first publicly disclosed the incident and whether the post-breach measures it is taking to protect consumers are adequate.

News that three senior Equifax executives sold nearly $2 million worth of their shares in the company in the days immediately following breach discovery has added to concerns about the company's commitment to addressing what went wrong.

Multiple lawsuits already have been filed over the breach, including one in Portland, Oregon, which seeks a mind-boggling $70 billion in damages nationwide.

On Monday two high-ranking lawmakers—Senators Orrin Hatch (R-Utah) and Ron Wyden (D-Oregon)—announced the first of what is sure to be multiple inquiries into the impact of the incident on U.S. agency records. The two Senators also wanted to know when exactly the three Equifax executives who sold their stock were first informed of the breach.

"Equifax has made a number of critical missteps, which have caused the public to question whether or not they truly have the best interests of their customers at heart," says Michael Sutton, CISO of ZScaler. "Whether it's the Equifax executives selling shares days after the discovery of the breach…or profiting from the breach by pushing a credit monitoring service that they own, the optics have been horrible."

Equifax had plenty of time to prepare a better response, Sutton says. The company should have known there would be a tsunami of concern following the breach disclosure and put in place measures for handling questions from concerned consumers.

"Equifax badly bungled the release of the website meant to provide answers. There were initially connectivity problems, and once it came online, it provided limited and sometimes contradictory information, even responding to nonsense requests," Sutton notes. The website was a critical component of the communication strategy and should have been thoroughly vetted before it went live.

Chris Pogue, global head of security at Nuix, predicts that the data compromise will likely result in the biggest class-action lawsuit in data breach history. "They'll probably debate the defensible position of reasonableness, which asks, 'Did Equifax do what was reasonable to protect this data?'" Pogue says. "In my opinion, they would be hard-pressed to find a security expert who says they took those steps." 

All of the public statements that Equifax has made about the breach so far are likely carefully vetted by lawyers because the company knows it is going to court over this. So, when the full details emerge, things are going to get far worse for Equifax, Pogue predicts.

Related Content:

 

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
9/13/2017 | 2:52:04 PM
Too stupid to believe
I have found an article on linkedin indicative that an Equifax website based in Argentina (and limited thereto) was secured by the highly innovative user-password combination of ...... sitting down security professionals?  Have a strong drink at the side???

Here: admin / admin

True.
20 Questions to Ask Yourself before Giving a Security Conference Talk
Joshua Goldfarb, Co-founder & Chief Product Officer, IDDRA,  10/16/2017
Printers: The Weak Link in Enterprise Security
Kelly Sheridan, Associate Editor, Dark Reading,  10/16/2017
Hyatt Hit With Another Credit Card Breach
Dark Reading Staff 10/13/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.