Washington, D.C. – U.S. Senator Catherine Cortez Masto (D-Nev.) joined a letter led by Senator Brian Schatz (D-Hawaii), to the Consumer Financial Protection Bureau (CFPB) which expresses concerns about recent reports that the bureau has halted its investigation into the massive Equifax data breach, which compromised the personal information of 145.5 million Americans.
“We are deeply troubled by recent news reports that, under Director Mulvaney’s leadership, the CFPB may have stopped its investigation into the Equifax breach,” the senators wrote. “According to these reports, the CFPB has not taken even the most preliminary steps to conduct an investigation. While we are aware of reports that the Federal Trade Commission (FTC) may be taking the lead in investigating Equifax’s failure to maintain adequate data security standards, the CFPB still has a duty to investigate the harm to consumers and whether other federal consumer financial laws have been violated.”
In addition to demanding confirmation that the investigation into Equifax is continuing, the senators also requested that the CFPB release details on potential plans to conduct on-site exams of Equifax and other large credit bureaus.
In addition to Senators Cortez Masto and Schatz, the letter was signed by U.S. Senators Robert Menendez (D-N.J.), Elizabeth Warren (D-Mass.), Sherrod Brown (D-Ohio), Jeanne Shaheen (D-N.H.), Jon Tester (D-Mont.), Chris Van Hollen (D-Md.), Tom Udall (D-N.M.), Heidi Heitkamp (D-N.D.), Tammy Duckworth (D-Ill.), Jeffrey A. Merkley (D-Ore.), Jack Reed (D-R.I.), Edward J. Markey (D-Mass.), Joe Donnelly (D-Ind.), Tina Smith (D-Minn.), Tammy Baldwin (D-Wis.), Kristen Gillibrand (D-N.Y.), Gary C. Peters (D-Mich.), Patty Murray (D-Wash.), Bernard Sanders (I-Vt.), Richard Blumenthal (D-Conn.), Angus S. King, Jr. (I-Maine), Ron Wyden (D-Ore.), Margaret Wood Hassan (D-N.H.), Dianne Feinstein (D-Calif.), Mark R. Warner (D-Va.), Amy Klobuchar (D-Minn.), Debbie Stabenow (D-Mich.), Richard J. Durbin (D-Ill.), and Christopher S. Murphy (D-Conn.).
A full copy of the letter can be found HERE and below:
Dear Acting Director English and Director Mulvaney,
We write to express serious concerns that, according to recent news reports, the Consumer Financial Protection Bureau (CFPB) may have halted an investigation into the massive Equifax data breach, which compromised the personal information of 145.5 million Americans.
The Equifax breach exposed significant gaps in cybersecurity standards in an industry that collects a substantial amount of personal information on virtually every adult in the country. The three largest consumer reporting agencies alone collect information on more than 200 million Americans—information that is used in more than 3 billion consumer reports a year. The data collected and reported by consumer reporting agencies determines Americans’ access to credit and the cost of that credit for individuals and small businesses. This data also impacts Americans’ ability to get a job or secure housing. By letting criminals gain access to its databases, Equifax has put nearly half the US population at risk for identity theft and fraud, which can ruin the financial lives of its victims and increase risk in our financial system.
Unfortunately, in the immediate aftermath of the breach, Equifax’s response caused more consumer harm and confusion. Just to name a few examples, the company responded by promoting its affiliated paid credit monitoring service (i.e., LifeLock), asking consumers to waive their rights to access free credit monitoring, and charging consumers to protect their data by freezing their credit reports. Not only do we need to better understand how this breach has impacted consumers, we also must ensure that consumer reporting agencies are taking the steps necessary to mitigate this harm—not misleading consumers or taking advantage of the situation for their own financial gain.
As established by the Dodd-Frank Wall Street Reform and Consumer Protection Act, the CFPB has a statutory mandate to implement and enforce federal consumer protection laws. This mandate specifically includes protecting consumers from “unfair, deceptive, or abusive acts and practices” and ensuring that “federal consumer financial laws are enforced consistently.” Dodd-Frank specifically includes the Fair Credit Reporting Act as one of the enumerated federal consumer financial laws. The CFPB also has clear supervisory authority over the largest consumer reporting agencies. Consumer reporting agencies and the data they collect play a central role in consumers’ access to credit and the fair and competitive pricing of that credit. Therefore, the CFPB has a duty to supervise consumer reporting agencies, investigate how this breach has or will harm consumers, and bring enforcement actions as necessary.
We are deeply troubled by recent news reports that, under Director Mulvaney’s leadership, the CFPB may have stopped its investigation into the Equifax breach. According to these reports, the CFPB has not taken even the most preliminary steps to conduct an investigation. While we are aware of reports that the Federal Trade Commission (FTC) may be taking the lead in investigating Equifax’s failure to maintain adequate data security standards, the CFPB still has a duty to investigate the harm to consumers and whether other federal consumer financial laws have been violated. We are also concerned that the CFPB appears to be scaling back its supervision of large consumer reporting agencies. The agency has reportedly scrapped plans to conduct on-site exams of Equifax and other consumer reporting agencies and turned down offers from the Federal Reserve, Federal Deposit Insurance Corporation, and Office of the Comptroller of the Currency to help with such on-site exams.
The responsibility of consumer reporting agencies as custodians of consumers’ personal and financial information is of paramount importance to us and our constituents. Several committee’s in both the House and Senate have held hearings to investigate the causes of the breach and the inadequate post-breach response. The CFPB has a statutory mandate to participate in this process by conducting an investigation. If that investigation exposes wrongdoing or consumer harm, the CFPB has the authority, and indeed a duty, to bring appropriate enforcement actions.
We respectfully ask for more information about the CFPB’s actions with respect to investigating the Equifax breach. Specifically, please answer the following questions by February 19, 2018:
- In September, then-CFPB Director Richard Cordray announced that the CFPB would begin a probe into the Equifax breach. Has the CFPB stopped this or any other investigation related to this matter?
- If so, why was that or any investigation halted?
- Who directed the ending of any investigation?
- Is the CFPB planning to conduct on-site exams of Equifax and the other credit bureaus under its supervisory authority?
- Has the CFPB conducted an examination of a consumer reporting agency following the Equifax hack?
- If the CFPB is conducting an investigation, what specific steps has the CFPB taken pursuant to this investigation?
- Has the CFPB issued Civil Investigative Demands (CIDs)?
- Has the CFPB interviewed Equifax personnel?
- Have the CFPB personnel examined Equifax systems or gone onsite to Equifax facilities?
- Is the CFPB coordinating with the FTC, state law enforcement officials, or other Federal regulators in their investigations?
Thank you for your prompt attention to this important issue.