The UK financial regulator, FCA , has fined Equifax Ltd. more than £11 million ($13.4 million) over a major data breach in 2017 , during which consumer data was stolen
The Financial Conduct Authority (FCA) announced the fine today, October 13, 2023. The FCA said that Equifax's UK business failed to take appropriate measures to protect the data of 13.8 million British consumers, held by its US-based parent company.

In 2017, the company confirmed a data breach of 143 million records. The incident was discovered in July 2017, but was publicly disclosed in September of that year.
Equifax: Data breach could have been avoided
The attackers exploited an Apache Struts to gain access to sensitive information.
See also: Shadow: Warns of customer data breach
They were able to find information about UK consumers because Equifax Ltd. had sent data to Equifax Inc. servers in the US. The stolen data included names, phone numbers, dates of birth, Equifax member logins, some credit card details and home addresses .
The FCA ruled that the theft of UK consumer data was “entirely preventable”. However, because Equifax did not treat its relationship with its parent company as outsourcing, it did not provide sufficient oversight over how the data it sent was managed and protected . In fact, it was known that there were “known weaknesses in Equifax Inc’s data security systems”.
The regulator noted that Equifax Ltd did not realise that UK consumer data had been breached until six weeks after its parent company discovered the hack. The UK business was informed just five minutes before the official announcement in September 2017
See also: Air Canada: BianLian group behind data breach?
So, UK customers were slow to learn that they had been affected by a major data breach.

Equifax: Accused of making misleading statements about data breach
The FCA also said that Equifax Ltd's public statements about the impact of the data breach "gave an inaccurate picture of the number of consumers affected."
He added that the company mishandled consumer complaints, failing to maintain quality assurance checks for complaints.
Jessica Rusu , FCA Chief Data, Information and Intelligence Officer , said the severe penalty highlights the fact that cybersecurity and data protection are vital to the safety and stability of financial services.
See also: Air Europa – data breach: Customers urged to cancel their credit cards
Both businesses and consumers must perceive the need for data protection, not only as an obligation, but also as a necessary social responsibility.
In 2017, Equifax, one of the largest companies in its industry, suffered one of the largest data breaches. This breach exposed the inadequacy of the data protection measures and security technologies the company had adopted.
Learning from Equifax
The Equifax case teaches us a lot. Above all, it highlights the power and punitive role that regulators can play in relation to protection . The £11 million fine is indeed severe, higher than previous ones imposed in similar cases. It shows the need for increased protection measures.
Although Equifax has taken action, businesses worldwide must continue to examine this example to improve.
Source: www.infosecurity-magazine.com
