In re Equifax, Inc.

362 F. Supp. 3d 1295
District Court, N.D. Georgia·Decided January 28, 2019·No. MDL DOCKET NO. 2800; 1:17-md-2800-TWT·Published·Cited by 44 cases

Opinion

THOMAS W. THRASH, JR., United States District Judge

This is a data breach case. It is before the Court on the Defendants' Motion to Dismiss the Consolidated Consumer Class Action Complaint [Doc. 425]. For the reasons set forth below, the Defendants' Motion to Dismiss the Consolidated Consumer Class Action Complaint [Doc. 425] is GRANTED in part and DENIED in part.

I. Background

On September 7, 2017, the Defendant Equifax Inc. announced that it was the subject of one of the largest data breaches in history.1 From mid-May through the end of July 2017, hackers stole the personal and financial information of nearly 150 million Americans.2 During this time period, Equifax failed to detect the hackers' presence in its systems, allowing the hackers to exfiltrate massive amounts of sensitive personal data that was in the company's custody.3 This data breach ("Data Breach") is unprecedented - it affected almost half of the entire American population.4 The Data Breach was also severe in terms of the type of information that the hackers were able to obtain. The hackers stole at least 146.6 million names, 146.6 million dates of birth, 145.5 million Social Security numbers, 99 million addresses, 17.6 million driver's license numbers, 209,000 credit card numbers, and 97,500 tax identification numbers.5 This is extremely sensitive personal information. Using this information, identity thieves can create fake identities, fraudulently obtain loans and tax refunds, and destroy a consumer's credit-worthiness.6

Equifax Inc. is a Georgia corporation with its principal place of business in Atlanta, *1309Georgia.7 Equifax is the parent company of the Defendants Equifax Information Services LLC and Equifax Consumer Services LLC.8 Both of those subsidiary companies are Georgia limited liability companies, with their principal places of business in Atlanta, Georgia.9 The Defendants operate together as an integrated consumer reporting agency.10 The Plaintiffs are 96 consumers who allege that they have been injured by the Data Breach. They allege that they are suffering a "present, immediate, imminent, and continuing increased risk of harm" due to the compromise of their personally identifiable information in the Data Breach.11 The Plaintiffs seek to represent a class of those similarly situated consumers in the United States who were injured by the Data Breach.12

Equifax's business model entails aggregating data relating to consumers from various sources, compiling that data into credit reports, and selling those reports to lenders, financial companies, employers, and others.13 Credit reporting agencies are "linchpins" of the nation's financial system due to the importance of credit reports in decisions to extend credit.14 Equifax also sells this information directly to consumers, allowing consumers to purchase their credit files and credit scores.15 In recent years, Equifax has worked to rapidly grow its business. Recognizing the value in obtaining massive troves of consumer data, Equifax has aggressively acquired companies with the goal of expanding into new markets and acquiring new sources of data.16 Equifax now maintains information on over 820 million individuals and 91 million businesses worldwide.17

Equifax recognized the importance of data security, and the value of the data in its custody to cybercriminals. Equifax observed other major, well-publicized data breaches, including those at Target, Home Depot, Anthem, and its competitor Experian.18 Equifax held itself out as a leader in confronting such threats, offering "data breach solutions" to businesses.19 It also acquired two identity theft protection companies, Trusted ID and ID Watchdog.20 Equifax was also the subject of several prior data breaches. From 2010 on, Equifax suffered several different data breach incidents highlighting deficiencies in its cybersecurity protocol.21 Given these prior breaches, cybersecurity experts concluded that Equifax was susceptible to a major data breach.22 Analyses of Equifax's cybersecurity demonstrated that it lacked basic maintenance techniques that are *1310highly relevant to potential data breaches.23 However, despite these risks, Equifax did little to improve its cybersecurity practices. Equifax's leaders afforded low priority to cybersecurity, spending a small fraction of the company's budget on cybersecurity.24

The story of the Data Breach begins on March 6, 2017. On that date, a serious vulnerability in the Apache Struts software was discovered and reported.25 This software, a popular open-source program, was used by Equifax in its consumer dispute portal website.26 The next day, the Apache Software Foundation issued a free patch and urged all users to immediately implement the patch.27 The Department of Homeland Security also issued warnings concerning this vulnerability.28 Equifax internally disseminated the warning, but never implemented the patch.29 Then, beginning on May 13, 2017, hackers were able to manipulate the Apache Struts vulnerability to access Equifax's systems, and using simple commands determined the credentials of network accounts that allowed them to access the confidential information of millions of American consumers.30 From May 13 to July 30, 2017, the hackers remained undetected in Equifax's systems.31 During this time, the hackers were able to steal the sensitive personally identifiable information of approximately 147.9 million American consumers.32 The personally identifiable information that hackers obtained in the Data Breach includes names, addresses, birth dates, Social Security numbers, driver's license information, telephone numbers, email addresses, tax identification numbers, credit card numbers, credit report dispute documents, and more.33

On July 29, 2017, Equifax's security team noticed "suspicious network traffic" in the dispute portal.34 The next day, the consumer dispute portal was deactivated and taken offline.35 On July 31, 2017, Equifax's CEO Richard Smith was informed of the breach.36 On August 2, 2017, Equifax informed the Federal Bureau of Investigation about the Data Breach, and retained legal counsel to guide its investigation.37 Equifax also hired cybersecurity firm Mandiant to investigate the suspicious activity.38 On September 7, 2017, seven weeks after discovering suspicious activity, Equifax publicly disclosed the Data Breach in a press release.39 Experts have since opined that the Data Breach was the result of weak cybersecurity measures and Equifax's low priority for data security.40

Free access — add to your briefcase to read the full text and ask questions with AI

In re Equifax, Inc., 362 F. Supp. 3d 1295 (N.D. Ga. 2019).

362 F. Supp. 3d 1295 (In re Equifax, Inc.) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related