The Equifax data breach exposed more of consumers’ personal information than the company first disclosed last year, according to documents given to lawmakers.
The credit-reporting company announced in September that the personal information of 145.5 million consumers had been compromised in a data breach. It originally said that the information accessed included names, Social Security numbers, birth dates, addresses and — in some cases — driver’s license numbers and credit card numbers. It also said the personal information from thousands of dispute documents was accessed.
However, Atlanta-based Equifax Inc. recently disclosed in a document submitted to the Senate Banking Committee, which was shared with Associated Press, that a forensic investigation found criminals accessed other information from company records. That included tax identification numbers, email addresses and phone numbers. Details, such as the expiration dates for credit cards or issuing states for driver’s licenses, were also included in the list.
The additional insight into the massive breach was first reported by the Wall Street Journal.
Equifax’s disclosure, which it has not made directly to consumers, underscores the granular detail the company keeps on individuals that it may have put at risk. And it adds to the string of missteps the company has made in recovering from the security debacle.
Equifax spokeswoman Meredith Griffanti said that “in no way did we intend to mislead consumers.” The company last year disclosed only the information that affected the greatest number of consumers and wanted to “act with the greatest clarity” in terms of the information provided the committee, she said.
Griffanti also said that although the list provided to the committee includes all of the potential data points that may have been accessed by criminals, those elements affected a minimal portion of consumers. And some data — like passport numbers — were not stolen. The company reiterated that the total number of consumers affected is unchanged.
“When you are making that kind of announcement, where do you draw the line? If you saw the list we provided the banking finance committee it was pretty exhaustive,” Griffanti said. “We wanted to show them that no stone was unturned.”
But to consumers whose information was exposed, it may feel like yet another slap in the face.
Equifax waited months to disclose the hack. After it did, anxious consumers experienced jammed phone lines and uninformed company representatives. An Equifax website set up to help people determine their exposure was described as sketchy by security experts and provided inconsistent and unhelpful information to many. The company blamed the online customer help page’s problems on a vendor’s software code after it appeared that it had been hacked as well.
Equifax has tried to make changes, replacing its chief executive, as well as spending millions to research and rectify the breach. In January, it launched a service that allows consumers to lock and unlock their credit report. But a test of the site by the New York Times found it unusable in many ways. The company said this experience was an exception and it has made some key changes to the service since it first launched.
The company continues to deal with multiple regulatory investigations into the matter, as well as hundreds consumer lawsuits. Sen. Elizabeth Warren (D-Mass.) released a report on the hack Wednesday that described it as “one of the largest and most significant data security lapses in history.”