Data Breach Exposed Personal Information of More Than 4.6 Million Michiganders
WASHINGTON, DC – U.S. Senators Gary Peters and Debbie Stabenow today joined 30 of their colleagues in a letter to Office of Management and Budget Director Mick Mulvaney and Consumer Financial Protection Bureau (CFPB) Acting Director Leandra English demanding answers on why the CFPB has reportedly halted its investigation into the Equifax data breach that exposed the Social Security numbers and personal identification information of more than 145 million Americans, including more than 4.6 million Michiganders.
“We are deeply troubled by recent news reports that, under Director Mulvaney’s leadership, the CFPB has stopped its investigation into the Equifax breach,” the senators wrote. “The CFPB is currently the only federal agency with supervisory authority over the largest consumer reporting agencies. Consumer reporting agencies and the data they collect play a central role in consumers’ access to credit and the fair and competitive pricing of that credit. Therefore, the CFPB has a clear duty to supervise consumer reporting agencies, investigate how this breach has or will harm consumers, and bring enforcement actions as necessary.”
According to reports, CFPB has not issued any subpoenas, sought testimony from key executives at Equifax, or proceeded with on-site examinations.
The Equifax breach exposed data that included consumers’ names, Social Security numbers, birthdates, addresses, driver’s license numbers, and, for some consumers, credit card numbers. This data could easily be used by criminals to steal identities or commit fraud, and consumers could suffer long-lasting damage to their credit, including being denied loans, mortgages, employment, or even rental housing.
Peters and Stabenow were joined in sending the letter by U.S. Senators Brian Schatz (D-HI), Bob Menendez (D-NJ), Elizabeth Warren (D-MA), Sherrod Brown (D-OH), Jeanne Shaheen (D-NH), Jon Tester (D-MT), Chris Van Hollen (D-MD), Tom Udall (D-NM), Heidi Heitkamp (D-ND), Tammy Duckworth (D-IL), Catherine Cortez Masto (D-NV), Jeff Merkley (D-OR), Jack Reed (D-RI), Ed Markey (D-MA), Joe Donnelly (D-IN), Tina Smith (D-MN), Tammy Baldwin (D-WI), Kirsten Gillibrand (D-NY), Patty Murray (D-WA), Bernie Sanders (I-VT), Richard Blumenthal (D-CT), Angus King (I-ME), Ron Wyden (D-OR), Maggie Hassan (D-NH), Dianne Feinstein (D-CA), Mark Warner (D-VA), Amy Klobuchar (D-MN), Dick Durbin (D-IL), Chris Murphy (D-CT), and Doug Jones (D-AL).
The text of the letter is below and available here:
Dear Acting Director English and Director Mulvaney,
We write to express serious concerns that, according to recent news reports, the Consumer Financial Protection Bureau (CFPB) may have halted an investigation into the massive Equifax data breach, which compromised the personal information of 145.5 million Americans.
The Equifax breach exposed significant gaps in cybersecurity standards in an industry that collects a substantial amount of personal information on virtually every adult in the country. The three largest consumer reporting agencies alone collect information on more than 200 million Americans—information that is used in more than 3 billion consumer reports a year. The data collected and reported by consumer reporting agencies determines Americans’ access to credit and the cost of that credit for individuals and small businesses. This data also impacts Americans’ ability to get a job or secure housing. By letting criminals gain access to its databases, Equifax has put nearly half the US population at risk for identity theft and fraud, which can ruin the financial lives of its victims and increase risk in our financial system.
Unfortunately, in the immediate aftermath of the breach, Equifax’s response caused more consumer harm and confusion. Just to name a few examples, the company responded by promoting its affiliated paid credit monitoring service (i.e., LifeLock), asking consumers to waive their rights to access free credit monitoring, and charging consumers to protect their data by freezing their credit reports. Not only do we need to better understand how this breach has impacted consumers, we also must ensure that consumer reporting agencies are taking the steps necessary to mitigate this harm—not misleading consumers or taking advantage of the situation for their own financial gain.
As established by the Dodd-Frank Wall Street Reform and Consumer Protection Act, the CFPB has a statutory mandate to implement and enforce federal consumer protection laws. This mandate specifically includes protecting consumers from “unfair, deceptive, or abusive acts and practices” and ensuring that “federal consumer financial laws are enforced consistently.” Dodd-Frank specifically includes the Fair Credit Reporting Act as one of the enumerated federal consumer financial laws. The CFPB also has clear supervisory authority over the largest consumer reporting agencies. Consumer reporting agencies and the data they collect play a central role in consumers’ access to credit and the fair and competitive pricing of that credit. Therefore, the CFPB has a duty to supervise consumer reporting agencies, investigate how this breach has or will harm consumers, and bring enforcement actions as necessary.
We are deeply troubled by recent news reports that, under Director Mulvaney’s leadership, the CFPB may have stopped its investigation into the Equifax breach. According to these reports, the CFPB has not taken even the most preliminary steps to conduct an investigation. While we are aware of reports that the Federal Trade Commission (FTC) may be taking the lead in investigating Equifax’s failure to maintain adequate data security standards, the CFPB still has a duty to investigate the harm to consumers and whether other federal consumer financial laws have been violated. We are also concerned that the CFPB appears to be scaling back its supervision of large consumer reporting agencies. The agency has reportedly scrapped plans to conduct on-site exams of Equifax and other consumer reporting agencies and turned down offers from the Federal Reserve, Federal Deposit Insurance Corporation, and Office of the Comptroller of the Currency to help with such on-site exams.
The responsibility of consumer reporting agencies as custodians of consumers’ personal and financial information is of paramount importance to us and our constituents. Several committee in both the House and Senate have held hearings to investigate the causes of the breach and the inadequate post-breach response. The CFPB has a statutory mandate to participate in this process by conducting an investigation. If that investigation exposes wrongdoing or consumer harm, the CFPB has the authority, and indeed a duty, to bring appropriate enforcement actions.
We respectfully ask for more information about the CFPB’s actions with respect to investigating the Equifax breach. Specifically, please answer the following questions by February 19, 2018:
Thank you for your prompt attention to this important issue.