June's AI-picked stock updates now live. See what's new in Tech Titans, up 28.5% year to date.Unlock Stocks

UK regulator fines Equifax Ltd 500,000 pounds for 2017 security breach

Published 20/09/2018, 02:01
© Reuters. Credit reporting company Equifax Inc. offices are pictured in Atlanta
EFX
-

(Reuters) - A British regulator on Thursday fined credit reference company Equifax Inc 's UK arm, Equifax Ltd, 500,000 pounds for failing to protect the personal information of up to 15 million people in Britain during a 2017 cyber attack.

The Information Commissioner's Office (ICO) said in a statement its investigation found that although Equifax systems in the United States were compromised, Equifax Ltd was responsible for the personal information of its customers in Britain.

Equifax said its UK office received the Monetary Penalty Notice from the ICO on Wednesday and was evaluating the notice and its response.

Equifax added that it cooperated fully throughout the investigation.

The cyber attack, which took place between May 13 and July 30, 2017, affected 146 million Equifax customers globally, the ICO said.

The British arm of the company failed to take appropriate steps to ensure its American parent company, Equifax Inc (NYSE:EFX), which was processing the data on its behalf, was protecting the information, the ICO said.

It said the investigation, carried out in parallel with the Financial Conduct Authority, revealed multiple failures at the company, which led to personal information being retained for longer than necessary and vulnerable to unauthorised access.

The personal information lost or compromised ranged from names and dates of birth to addresses, passwords, driving licences and financial details.

Equifax contravened five out of eight data protection principles of the Data Protection Act 1998, including failure to secure personal data, poor retention practices and lack of legal basis for international transfers of UK citizens' data, the ICO said.

The ICO found that measures that should have been in place to manage the personal information were inadequate and ineffective. Investigators found significant problems with data retention, IT system patching and audit procedures.

The investigation also found that the U.S. Department of Homeland Security had warned Equifax about a critical vulnerability as far back as March 2017 and that sufficient steps to address the vulnerability were not taken, the ICO said.

As a credit reporting agency, Equifax keeps vast amounts of consumer data for banks and other creditors to use to determine the chances of their customers' defaulting.

© Reuters. Credit reporting company Equifax Inc. offices are pictured in Atlanta

Equifax first disclosed in September 2017 that it had been the target of a massive data breach, mostly in the United States.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.