• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military

2

'We are rapidly running out of time': Watchdog sounds Social Security alarm after 22% cut confirmed for 2032

3

Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there

1

Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military

2

'We are rapidly running out of time': Watchdog sounds Social Security alarm after 22% cut confirmed for 2032

3

Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there
TechEquifax

Senators Want Answers From Equifax Over Its Massive Data Breach

Barb Darrow
By
Barb Darrow
Barb Darrow
Down Arrow Button Icon
Barb Darrow
By
Barb Darrow
Barb Darrow
Down Arrow Button Icon
September 12, 2017, 7:52 AM ET

The hits just keep coming for Equifax in the wake of last Thursday’s disclosure of a security breach that may have exposed personal data on up to 143 million people.

Late Monday, the U.S. Senate Committee on Finance informed Equifax CEO Richard Smith that it wants to hear more—a lot more—about the breach. Senators want more information specifically about the types of data that may have been accessed beyond social security numbers and birthdates. Information on some 200,000 credit card holders may have also been compromised. And the committee really wants to know what safeguards Equifax had been using to keep consumer data secure.

In its letter, which is copied in the committee’s press release, the committee asked if Equifax (EFX) has a chief information security officer (CISO) and, if so, to whom that executive reports. The committee also wants a tally of how many employees are dedicated to data security and how often Equifax used an outside experts to conduct penetration tests of both internal and external systems in the past two years.

Companies typically conduct penetration, or “pen tests,” by security experts to find vulnerabilities that could be exploited before bad guys can find and exploit them.

In the days since Equifax disclosed the breach on September 7, claims and counterclaims have swirled around the cause. All Equifax itself has said is that “criminals exploited a U.S. website application vulnerability to gain access to certain files.”

Clearly, more information is needed by regulators and consumers alike. Equifax’s response to date has been slammed. Critics said the company used the breach to tout its own paid credit protection services. Additionally, the website it put up to help customers figure out if they were impacted, itself posed security problems.

Related: Equifax Could Make $700 Million Off Its Own Breach

“The scope and scale of this breach appears to make it one of the largest on record, and the sensitivity of the information compromised may make it the most costly to taxpayers and consumers,” according to the letter from the committee, which is chaired by by Orrin Hatch (R-Utah) with ranking Democrat Ron Wyden (D-Ore.).

The committee also wants to hear about an earlier breach in which W-2 and employee records data was taken from TALX, an Equifax subsidiary that handles payroll for companies.

On Friday, Jeb Hensarling, (R.-Texas) said the House Financial Services Committee wants its own look into the Equifax mess.

Get Data Sheet, Fortune’s technology newsletter.

There have been third-hand claims that Equifax’s use of particular piece of open-source software is at the core of this problem. But that’s a red herring, says a long-time security consultant. He requested anonymity because he works for government agencies and is not authorized to speak to the media.

“Forget the particular patches or bugs,” he says. “What is Equifax’s overall approach to security? Does it work with third-party auditors and security folks to protect what is essentially a good chunk of the U.S. economy?”

All software, including aging Java software that is used by most Fortune 500 and other large companies, has vulnerabilities. And that is true even if those companies use a commercially supported version of open-source software purchased from a vendor. Those frailties, if found by criminals before a company’s own security experts, can and will be exploited.

The issue here is how much due diligence this credit agency put into bullet-proofing that software. And that is apparently what the senators on the Finance Committee aim to find out.

The Committee set a deadline of September 28 for Equifax to respond.

About the Author
Barb Darrow
By Barb Darrow
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Xbox CEO Asha Sharma
SuccessCareers
Xbox’s CEO spent her early career taking out trash and selling coupon books—she says the secret to her rise was never obsessing over a dream career
By Preston ForeJune 10, 2026
2 hours ago
Boris Cherny, Head of Claude Code
SuccessHiring
The architect behind Claude Code reveals the three things Anthropic looks for in a good hire—and why people with low ego are a must
By Emma BurleighJune 10, 2026
3 hours ago
Trump sits at the Resolute Desk with his hands folded
AIImmigration
OpenAI and Nvidia CEOs didn’t flinch at Trump’s $100,000 H-1B visa fee, and now they’re paying up as their application numbers soar
By Jacqueline MunisJune 10, 2026
3 hours ago
Current price of Ethereum for June 10, 2026
Personal FinanceEthereum
Current price of Ethereum for June 10, 2026
By Joseph HostetlerJune 10, 2026
4 hours ago
goldman
Investingprivate equity
‘The circulatory system isn’t working.’ Goldman on what’s really wrong with private markets
By Nick LichtenbergJune 10, 2026
5 hours ago
Exclusive: Mastercard launches protocol to let AI agents pay each other, send micropayments
BankingMastercard
Exclusive: Mastercard launches protocol to let AI agents pay each other, send micropayments
By Ben WeissJune 10, 2026
5 hours ago

Most Popular

Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military
Asia
Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military
By Kate O'Keeffe and BloombergJune 8, 2026
2 days ago
'We are rapidly running out of time': Watchdog sounds Social Security alarm after 22% cut confirmed for 2032
Economy
'We are rapidly running out of time': Watchdog sounds Social Security alarm after 22% cut confirmed for 2032
By Nick LichtenbergJune 9, 2026
1 day ago
Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there
Success
Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there
By Preston ForeJune 8, 2026
2 days ago
Current price of oil as of June 9, 2026
Personal Finance
Current price of oil as of June 9, 2026
By Joseph HostetlerJune 9, 2026
1 day ago
Current price of silver as of Tuesday, June 9, 2026
Personal Finance
Current price of silver as of Tuesday, June 9, 2026
By Joseph HostetlerJune 9, 2026
1 day ago
Wall Street dumped nearly $1 trillion in tech stocks by midday—then clawed it back and bought peanut butter and paint
Investing
Wall Street dumped nearly $1 trillion in tech stocks by midday—then clawed it back and bought peanut butter and paint
By Eva RoytburgJune 9, 2026
20 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.