Equifax (NYSE:EFX) Ltd, a subsidiary of blue-chip credit agency Equifax (NYSE:EFX) Inc, has been fined more than £11 million by the UK Financial Conduct Authority (FCA) for its failure to oversee and secure UK consumer data outsourced to its US-based parent company.
In 2017, a significant cybersecurity breach at Equifax exposed the personal data of approximately 13.8 million UK customers.
The breach contained sensitive information, including names, dates of birth, phone numbers, login details, partially exposed credit card details, and residential addresses.
According to the FCA, the breach, one of the largest in history, should have been prevented, highlighting systemic weaknesses in the company’s data security protocols.
Following the breach, Equifax made several public statements on the impact of the incident to UK consumers which gave an inaccurate impression of the number of consumers affected, said the watchdog.
The FCA also said that Equifax treated consumers unfairly by failing to maintain quality assurance checks for complaints following the incident, causing complaints to be mishandled.
Therese Chambers, joint executive director of enforcement and market oversight at the FCA, stated: "Financial firms hold data on customers that is highly attractive to criminals. They have a duty to keep it safe and Equifax failed to do so.
“They compounded this failure by the ways they mishandled their response to the data breach. Regulated firms are on the hook, regardless of whether they outsource or not."
Jessica Rusu, FCA chief data, information, and intelligence officer, added: "Cybersecurity and data protection are of growing importance to the security and stability of financial services.
“Firms not only have a technical responsibility to ensure resiliency but also an ethical responsibility in the processing of consumer information. The Consumer Duty makes it clear that firms must raise their standards."