4 ms·
It seems absurd that they only need to allocate $31 million for "alternative payments" while the old CEO leaves with close to $20 million in bonuses [0], while
by jpetrucc 7y ago
It seems absurd that they only need to allocate $31 million for "alternative payments" while the old CEO leaves with close to $20 million in bonuses [0], while the rest of the money in the settlement is basically reserved for them to pay themselves for their "free" credit monitoring.
This whole situation was a good opportunity to set a precedent for companies not taking data security seriously. But they've instead shown everyone that you can really just ignore all of that and hope it's never discovered - even if it is, it's really just a light slap on the wrist. Combining this with the recent Facebook fine [1], it really makes me think that the FTC has become a complete joke.
[0]: https://www.cbsnews.com/news/equifax-data-breach-settlement-disgraced-former-ceo-getting-nearly-20-million-in-bonuses-after-the-hack/ https://www.cbsnews.com/news/equifax-data-breach-settlement-...
[1]: https://www.theverge.com/2019/7/12/20692524/facebook-five-billion-ftc-fine-embarrassing-joke https://www.theverge.com/2019/7/12/20692524/facebook-five-bi...
- basch 7y agoWhat I want to know is how they established part of the settlement for damages caused by the breach, yet there is 0 evidence that any of the data has ever become public. How would someone prove they were affected, if nobody was affected?
- jiveturkey 7y agoAs I've noted before, PII is not, in fact, toxic.
- triangleman 7y agoYou had me until you mentioned the Facebook fine. $5 billion, assuming it stands, is a lot of money and a good deterrent against the kind of behavior FB was engaged in. No shareholder would be happy that their company lost that much money. And before someone retorts with the fact that the stock went up the day the fine was announced: shareholders could be happy that the uncertainty is over, but still not happy with the fine.
- bradknowles 7y agoNah. They’ll make that back in a few minutes. If you’re not talking about a sizable portion of their gross annual revenue or their total market capital, you’re going to have little or no effect on any corporation. If you really want to have an effect on a corporation, the only way to do that is to pierce the corporate veil, and hold the senior executives and the board members personally liable. That will get them to change big time, and in a hurry. When you endanger the mega yachts and the private islands, you’ll get them to sit up and take notice.
- paulrpotts 7y agoYou had _me_ until you claimed this was a "good deterrent." $5 billion is a bit over ten percent of 2018 revenue. It's not enough to keep anyone up at night or, more importantly, convince them to do anything substantive _at all_ to improve privacy - because their revenue is _growing_ much more than $5bn a year.
- davvolun 7y agoWhile I agree that this factor is stupid -- either it wasn't well-thought or it was intended to be a way to avoid fairly compensating victims, whatever. That said, they are paying a total of about $700M, in fees and compensation and so. The actual amount is probably going to be less -- if every single person took the $125, then the $31M for credit monitoring wouldn't be used at all. But for comparison, in Q2 2019, Equifax report about $900M in revenue. So they lost a full quarter of profit out of this. Is that fair? Does that actually give sufficient incentive to keep this from happening again, by Equifax, or by TransUnion/Experian? I don't know. I can say I'm not happy about this, the golden parachutes are bullshit, how they sat on the hack and then tried to scapegoat an engineer over it is infuriating, but I'm sure they are scrambling to lock down their security now, if not before, and I can't realistically see the current CEO letting something like this happen again. Although, as they say, lightning never strikes the same place twice -- they'll lock down these avenues, but what are they going to miss? Can we actually trust them not to leave other vulnerabilities? We don't really have a choice, do we? I can't opt out of their "service."
- paulgb 7y ago> It seems absurd that they only need to allocate $31 million for "alternative payments" while the old CEO leaves with close to $20 million in bonuses. Not to mention the $77.5 million that goes to the lawyers who negotiated this settlement on our behalf (per the settlement).
- Someone1234 7y agoThis also: > It was also revealed that three Equifax executives sold almost $1.8 million of their personal holdings of company shares days after Equifax discovered the breach but more than a month before the breach was made public.[0] Nobody was prosecuted as a result. They were literally promoting their own $16.95/month credit monitoring product (ID Patrol) on the original website about the breach before they were shamed into taking it down. Executives profited. The CEO profited. The lawyers profited. And the shareholders lost little. The public is the only one paying the cost, and their information was largely shared with Equifax without express consent. [0] https://www.bloomberg.com/news/articles/2017-09-07/three-equifax-executives-sold-stock-before-revealing-cyber-hack https://www.bloomberg.com/news/articles/2017-09-07/three-equ...