A vulnerability in Apache Struts was made public in early March 2017 and rated critical. Equifax had a policy of applying such patches within forty-eight hours. It did not apply this one. By the time the company noticed, attackers had been inside for months, and the personal data of roughly 145 million Americans was gone. Richard Smith, who had run Equifax since 2005 and retired weeks before the hearing, appeared before House Financial Services on October 5, 2017.
Forty-eight hours
HensarlingMr. Smith, I am led to believe the Apache Struts CVE-20175638 vulnerability was first publicized in early March, at which point it was immediately categorized as a critical vulnerability by numerous cybersecurity authorities. What do you believe is a reasonable amount of time for a critical vulnerability patch to be pushed out and implemented on all affected applications?
SmithYes. Our policy, our program at the time was within 48 hours and we did that. We were notified--
HensarlingI am sorry. You did do that?
SmithYes.
HensarlingSo what happened?
SmithSo on the 8th of March we were notified, as you mentioned. On the 9th of March, following the standard protocol, the communication was disseminated to those who needed to know about the patch.
SmithTwo things happened, Mr. Chairman: One was a human error, an individual who was responsible for what we call the patching process did not ensure that there was communication and closed-loop communication to the person who needed to apply the patch. That was error number one.
SmithError number two was on the 15th of March, we used a technology called a scanning technology, which looks around the systems for vulnerabilities. That scanner, for some reason, did not detect the Apache vulnerability. So we had a human error, as I alluded to in my oral testimony, and a technological error, both resulting in the fact that it was not patched.
[Hearing transcript, October 5, 2017, questioning by Chairman Hensarling.]
The safeguards rule
Representative Maloney had written to the other two credit bureaus to ask how their patching worked. One of them answered in detail.
Maloneydo you believe that Equifax violated the FTC's safeguard rule?
SmithCongresswoman, I understand your point, and it is my understanding we were in compliance with the safeguards rule and that the safeguards rule does not prevent 100 percent against data breaches.
MaloneyHow in the world could you let this happen when you were warned by the Homeland Security Department?
MaloneyMy second question, the safeguard rule also requires you to have a patch management system, essentially a system in place to patch security flaws as soon as a fix for the flaw is released. But you have testified that your patch management system failed in this case, even though there was a patch released almost immediately.
SmithCongresswoman, a patch has to be identified. We are routinely notified from--
MaloneyIt was identified by the Homeland Security Department when they notified you. You already testified that your person failed to implement it.
[Hearing transcript, October 5, 2017, questioning by Rep. Maloney.]
The retirement package
VelazquezSo my question to you, sir, do you believe it is right for you to walk away with a payday worth $90 million when the lives of more than 145 million hardworking Americans had been potentially compromised?
SmithCongresswoman, one, again, I do deeply apologize for the breach to those American consumers.
SmithI have heard of this article. I can't reconcile that number. Let me be very clear. I was--
VelazquezHow much are you getting in your retirement package?
SmithWhen I retired, I did announce my retirement. And at that time--so I also told the board back in early September, mid-September that I would not take a bonus going forward. I also told the board that I would be an adviser, unpaid, helping the board and helping the management team for as long--and I asked for nothing beyond what was disclosed in the proxy, and that is a pension that I have accumulated over my career, and that is some equity that I have earned in the
[Hearing transcript, October 5, 2017, questioning by Rep. Velazquez.]
August 1
Representative Scott went to the calendar: the date Smith said he learned of the breach, and the date executives sold stock.
ScottIt is important for the American people to know that what we have before us is a despicable, a shameful situation for 145 million American citizens to lose the privacy of their Social Security numbers and all of that, but let it be known that it is the top management--it is you--who is responsible for this.
ScottNow, what disturbs me perhaps more than anything was the timeline. You said that you became knowledgeable about this breach on July the 31st, but here is what happened: On August 1st, your executives sold $2 million worth of stock. And not only that, Mr. CEO, former CEO, it was your chief financial officer who led that charge to sell that stock.
ScottNow, nobody is going to tell me you are getting information on July 31st and here they go dumping their stock less than 24 hours later. That has to be investigated and cleared if we are going to get the confidence of the American people back. So it is this insider trading; anybody can see that.
ScottAnd then the second thing, we need to make sure that these guys who sold that stock, who made $653,000 in savings from that stock with that inside information, that they pay that money back and that they are fired. 143 million people losing this is no justification.
[Hearing transcript, October 5, 2017, statement of Rep. Scott.]