• Home
  • News
  • Fortune 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechEquifax

Why Equifax Executives Will Get Away With the Worst Data Breach in History

By
Jeff John Roberts
Jeff John Roberts
Editor, Finance and Crypto
Down Arrow Button Icon
By
Jeff John Roberts
Jeff John Roberts
Editor, Finance and Crypto
Down Arrow Button Icon
September 16, 2017, 9:25 AM ET

Picture a factory gushing pollution into a nearby waterway. Now, imagine the factory’s executives knew a giant leak was likely but did nothing to prevent it. Finally, think of those same executives waiting weeks to warn anyone of the spill, and then bungling the clean-up efforts—after first trying to profit from them.

If all this happened, the company responsible would face criminal fines and its executives would likely end up in prison.

That’s why Equifax and its leadership team can count themselves lucky they’re in the data business. Even though their incompetence and foot-dragging compromised the security of over 140 million Americans, they’re beyond the reach of criminal law. Sure, Equifax may face class action suits and a FTC investigation, but the worst that can happen to individual executives is they will have to resign (two already have)—probably with a tidy payout on their way out.

It doesn’t have to be this way. According to Jesse Eisinger, author of a recent book about white collar crime, there’s ample precedent for corporate executives going to jail for negligence. In an interview with Fortune, Eisinger pointed to a rule called the “responsible corporate officer” doctrine, which prosecutors can use to charge executives whose lack of oversight endangers the public welfare.

The catch, though, is the “responsible officer” rule has only been deployed in cases involving food, drugs or the environment. Examples include executives who received criminal penalties over mislabeled oxycontin shipments, and whose negligence led to salmonella-tainted eggs.

According to David Frulla, a regulatory lawyer at Kelley Drye, prosecutors can only bring responsible officer charges in respect to a specific law, such as the FDCA, that provides criminal penalties for violators. They can’t simply charge Equifax executives for general incompetence.

Right now, there’s no such federal law when it comes to personal data. But there probably should be given the clear public harm that occurs after major data breaches—including the Equifax hack, which has been widely described as the worst in history.

In the case of Equifax, hackers plundered not only the name and Social Security numbers of more than 100 million people but, in many cases, their phone numbers and home addresses (past and present) as well. Those who paid for Equifax’s credit monitoring service also had their credit card information stolen.

All of that data is already for sale in dark corners of the Internet, and is going to lead to a spate of scams and identity thefts that will haunt people for years. Meanwhile, the website Equifax set up to help consumers find out if they had been breached has also been found vulnerable to hackers, and critics are accusing the company of using the breach to tout paid ID Theft products. Some sort of punishment is clearly in order.

Many people in cyber-security circles caution that shaming corporate hacking victims is not a good idea because companies will be less forthcoming about data breaches. This reasoning is not convincing in the case of Equifax, however. The company’s whole business revolves around personal data—their failure to protect it should mean public disgrace.

Equifax executives behaved with brazen carelessness, storing the data in a way that made it easy for hackers to try and steal it. Eventually, the hackers broke in because Equifax failed to update a critical piece of software, even though a patch had been available for months. It’s poor practice, these days, for consumers not to update the software on their home devices. For a giant corporation to ignore software updates is simply reckless, and even more so when that corporation’s core business involves consumer data.

Equifax executives will nonetheless face no legal consequences for this debacle (other than three officers who could face charges for selling stock before the breach was disclosed). The U.S. right now just doesn’t have the laws to hold them accountable. Meanwhile, CEO Richard Smith will probably keep the $68.9 million he’s made from selling the company’s shares since 2016.

This could change, however, if Senators Orrin Hatch (R-UT.) and Ron Wyden (D-Ore.) are serious about getting to the bottom of the Equinox breach. Their proposed investigation should seek to identify who at Equifax was responsible for the breach, and also propose ways for this not to happen again.

According to Sam Buell, who teaches corporate criminal law at Duke University School of Law, scandals like the Equifax affair often trigger public conversations that lead to new regulatory oversight.

“There’s a good argument this is one of those industries where there’s a need for a higher standard or the pain of criminal punishment. When you’re in a business that has the potential to do this scale of harm, you have a duty of care for your product that could be covered by criminal law.”

Consumers would no doubt agree. The time is rapidly coming when executives should be held to the same standard for protecting personal data as they do for the environment or the food supply.

About the Author
By Jeff John RobertsEditor, Finance and Crypto
LinkedIn iconTwitter icon

Jeff John Roberts is the Finance and Crypto editor at Fortune, overseeing coverage of the blockchain and how technology is changing finance.

See full bioRight Arrow Button Icon

Latest in Tech

AIMeta
It’s ‘kind of jarring’: AI labs like Meta, Deepseek, and Xai earned some of the worst grades possible on an existential safety index
By Patrick Kulp and Tech BrewDecember 5, 2025
10 hours ago
Elon Musk
Big TechSpaceX
Musk’s SpaceX discusses record valuation, IPO as soon as 2026
By Edward Ludlow, Loren Grush, Lizette Chapman, Eric Johnson and BloombergDecember 5, 2025
11 hours ago
data center
EnvironmentData centers
The rise of AI reasoning models comes with a big energy tradeoff
By Rachel Metz, Dina Bass and BloombergDecember 5, 2025
11 hours ago
netflix
Arts & EntertainmentAntitrust
Hollywood writers say Warner takeover ‘must be blocked’
By Thomas Buckley and BloombergDecember 5, 2025
11 hours ago
person
CybersecurityDigital
Dictionaries’ words of the year are trying to tell us something about being online in 2025
By Roger J. KreuzDecember 5, 2025
12 hours ago
Greg Peters
Big TechMedia
Top analyst says Netflix’s $72 billion bet on Warner Bros. isn’t about the ‘death of Hollywood’ at all. It’s really about Google
By Nick LichtenbergDecember 5, 2025
13 hours ago

Most Popular

placeholder alt text
Economy
Two months into the new fiscal year and the U.S. government is already spending more than $10 billion a week servicing national debt
By Eleanor PringleDecember 4, 2025
2 days ago
placeholder alt text
Success
‘Godfather of AI’ says Bill Gates and Elon Musk are right about the future of work—but he predicts mass unemployment is on its way
By Preston ForeDecember 4, 2025
2 days ago
placeholder alt text
Success
Nearly 4 million new manufacturing jobs are coming to America as boomers retire—but it's the one trade job Gen Z doesn't want
By Emma BurleighDecember 4, 2025
2 days ago
placeholder alt text
Success
Nvidia CEO Jensen Huang admits he works 7 days a week, including holidays, in a constant 'state of anxiety' out of fear of going bankrupt
By Jessica CoacciDecember 4, 2025
2 days ago
placeholder alt text
Real Estate
‘There is no Mamdani effect’: Manhattan luxury home sales surge after mayoral election, undercutting predictions of doom and escape to Florida
By Sasha RogelbergDecember 4, 2025
2 days ago
placeholder alt text
Economy
Tariffs and the $38 trillion national debt: Kevin Hassett sees ’big reductions’ in deficit while Scott Bessent sees a ‘shrinking ice cube’
By Nick LichtenbergDecember 4, 2025
2 days ago
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.