Summary
This 8-K filing from Equifax Inc. (EFX) provides an update on the cybersecurity incident disclosed on September 7, 2017, specifically detailing the impact on UK consumers. Equifax UK has completed its investigation and begun contacting approximately 693,665 affected UK consumers. The company has identified that a file containing 15.2 million UK records, dating from 2011-2016, was compromised. While this file contained a mix of actual consumer data, test data, and duplicates, Equifax has worked to identify and categorize the impacted individuals. The company has segmented affected UK consumers into four groups based on the type of data accessed, including email addresses, membership credentials, driving license numbers, and phone numbers. Equifax is offering these consumers various Equifax and third-party safeguards to protect against potential risks. For the remaining 14.5 million records, which may contain names and dates of birth, Equifax does not believe there is a significant risk to those individuals. The company's focus is on mitigating potential harm to those identified as being at higher risk.
Key Highlights
- 1Equifax UK has identified and begun notifying 693,665 affected UK consumers following a cybersecurity incident.
- 2A file containing 15.2 million UK records (2011-2016) was part of the compromised data.
- 3The compromised file included a mix of actual consumer data, test datasets, duplicates, and spurious fields.
- 4Equifax UK has categorized impacted consumers into four specific groups based on accessed data types (email, membership credentials, driving license numbers, phone numbers).
- 5The company is offering protective services and safeguards to the identified affected consumers.
- 6For the remaining 14.5 million records, Equifax believes the risk to individuals (name and DOB potentially exposed) is not significant.