Massachusetts AG sues Equifax over massive data breach – CNET

Online Security

First official enforcement action alleges company violated state data protection and privacy laws b

Getty Images

Massachusetts Attorney General Maura Healey filed a lawsuit against Equifax on Tuesday after a massive hack that exposed sensitive financial information for nearly half the US population.

The complaint, filed in Suffolk Superior Court, alleges the credit-reporting bureau violated Massachusetts consumer protection and data privacy laws by not installing appropriate safeguards.  The personal information for nearly 3 million Massachusetts residents was potentially exposed by the hack, according to the lawsuit.

“We are suing because Equifax needs to pay for its mistakes, make our residents whole, and fix the problem so it never happens again,” Healey said in a statement.

Meanwhile, Equifax’s Canadian division said Tuesday the hack may also affect about 100,000 consumers in that country.The company said the information that may have been compromised included names, addresses, social insurance numbers and in some cases credit card numbers.

Massachusetts’ lawsuit is the first official enforcement action in what is expected to be a massive legal onslaught against Equifax in the wake of hack that exposed the personal financial data from as many as 143 million people in the US, including names, Social Security numbers, birth dates and addresses of customers. A handful of attorneys general for other states, including New York, Illinois and Connecticut, and two prominent senators, have asked company for information about the hack.

The US Justice Department and Federal Trade Commission have opened investigations into the hack.

Some of the questions focus on nearly $1.8 million in stock sales made by Equifax executives, including the company’s chief financial officer, three days after the breach was discovered and several weeks before it was made public.

Equifax said last week the hack was made possible by a months-old but apparently unpatched web server vulnerability. Patches were made available for the flaw in mid-March, but it’s unclear why the flaw still existed on Equifax’s servers in mid-May.

On Friday, the company said Chief Security Officer Susan Mauldin and Chief Information Officer David Webb would be “retiring,” effective immediately.

Equifax didn’t immediately respond to a request for comment.

Solving for XX: The industry seeks to overcome outdated ideas about “women in tech.”

It’s Complicated: This is dating in the age of apps. Having fun yet? These stories get to the heart of the matter.


🕐 Top News in the Last Hour By Importance Score

# Title 📊 i-Score
1 Scientists crack case of 'demonic' sea lions terrorizing the West Coast 🟢 85 / 100
2 AI insurtech Ominimo bags its first investment at a $220M valuation 🔴 75 / 100
3 Your Wine Tariff Questions, Answered 🔴 72 / 100
4 LVMH’s Louis Vuitton factory in Texas plagued with errors, waste as it ranks among the worst-performing globally 🔴 72 / 100
5 Footballer, 21, tragically dies after horror collision with goalkeeper during match 🔴 65 / 100
6 Many primary school kids can't identify a slug – new initiative hopes to change that 🔴 65 / 100
7 NHS hospital data tracker: Search tool reveals how many patients are waiting for treatment at YOUR trust, as well as A&E delays and ambulance response times 🔴 65 / 100
8 Badenoch condones Tories forming pacts with Reform UK if necessary to take control of councils – UK politics live 🔵 59 / 100
9 The Real Cost of the Nintendo Switch 2 🔵 55 / 100
10 Minecraft obsessed teen boys are destroying movie theaters: ‘It’s disgusting’ 🔵 45 / 100

View More Top News ➡️