Equifax Ltd was handed down a £11,164,400 fine by the Financial Conduct Authority (FCA) for its failure to manage, monitor, and secure UK customer data. The negligence had led to one of the largest cybersecurity breaches in history, with hackers gaining access to the personal information of millions of individuals.
The breach in question happened in 2017, when Equifax Inc, the parent company of Equifax Ltd, experienced a cyber-attack that exposed the data of nearly 150 million customers. Equifax Ltd had outsourced UK customer data to Equifax Inc servers in the US, which led to 13.8 million UK customers being exposed in the attacks as well.
Information gleaned from the attack includes names, dates of birth, phone numbers, Equifax membership login details, partially exposed credit card details, and residential addresses. The breach, according to the FCA, was entirely preventable.
According to the FCA, the key issue was Equifax’s insufficient oversight of how the data being sent to the US was managed and protected. Moreover, Equifax Ltd was unaware of the breach until six weeks after Equifax Inc had detected it, being told only five minutes before its public announcement by the American parent company.
Following the announcement, the short warning led to difficulties in fielding customer complaints. Additionally, public statements regarding the impact of the attack provided inaccurate information, according to the FCA.
“Financial firms hold data on customers that is highly attractive to criminals. They have a duty to keep it safe and Equifax failed to do so,” said Therese Chambers, joint executive director of enforcement and market oversight.
“They compounded this failure by the ways they mishandled their response to the data breach. Regulated firms are on the hook, regardless of whether they outsource or not.”
Recommended
- Facial Recognition Firm Facing £17m ICO Data Handling Fine
- IBM & Equifax Join Fintech Scotland
- UK Treasury Committee Chairman Leaps on Equifax
In response to the fine, Equifax Ltd agreed to resolve the matter and qualified for a 30% discount under the FCA’s executive settlement procedures. Were it not for this discount, the financial penalty would have amounted to £15,949,200.
Equifax Ltd also received a 15% credit for mitigation, acknowledging its high level of cooperation during the investigation, voluntary redress offered to consumers, and the global transformation program instituted after the incident.
“Cyber security and data protection are of growing importance to the security and stability of financial services. Firms not only have a technical responsibility to ensure resiliency, but also an ethical responsibility in the processing of consumer information. The Consumer Duty makes it clear that firms must raise their standards,” said Jessica Rusu, FCA chief data, information and intelligence officer.





