Item 3. LEGAL PROCEEDINGS
12K characters. Original on sec.gov · Markdown
Item 3. LEGAL PROCEEDINGS
Cybersecurity Incident Litigation, Claims and Government Investigations. Following the 2017 cybersecurity incident, hundreds of class actions were filed by consumers against us in federal, state and Canadian courts relating to the cybersecurity incident. The plaintiffs in these cases, who purport to represent various classes of consumers, generally claim to have been harmed by alleged actions and/or omissions by Equifax in connection with the cybersecurity incident and assert a variety of common law and statutory claims seeking monetary damages, injunctive relief and other related relief. In addition, certain class actions have been filed by financial institutions who allege their businesses have been placed at risk due to the cybersecurity incident and generally assert various common law claims such as claims for negligence and breach of contract, as well as, in some cases, statutory claims. The financial institutions class actions seek compensatory damages and other related relief. Furthermore, a lawsuit has been filed by the City of Chicago with respect to the cybersecurity incident alleging violations of state laws and local ordinances governing protection of personal data, consumer fraud and breach notice requirements and business practices. Beginning on December 6, 2017 and pursuant to multiple subsequent orders, the U.S. Judicial Panel on Multidistrict Litigation ordered the consolidation and transfer for pre-trial proceedings with respect to the U.S. cases pending in federal court discussed above to the Northern District of Georgia as the single U.S. District Court for centralized proceedings. Based on this order, consolidated pre-trial hearings with respect to U.S. consumer and financial institution federal class actions related to the cybersecurity incident have begun in the Northern District of Georgia. In addition to these federal court proceedings, four putative class actions arising from the cybersecurity incident have been filed in the Fulton County Superior Court in Georgia. We have also appeared or notified the appropriate parties of representation in the Canadian class actions, but such actions are all at the preliminary stages. In addition, a civil enforcement action has been filed by the Attorney General of Massachusetts and a lawsuit has been filed by the City of San Francisco, each of which are in the initial pre-trial stages. We dispute the allegations in the complaints described above and intend to defend against such claims.
In addition, we continue to cooperate with federal, state, city and foreign governmental agencies and officials investigating or otherwise seeking information and/or documents, including through Civil Investigative Demands, regarding the cybersecurity incident and related matters, including 49 state Attorneys General offices, as well as the District of Columbia, the Federal Trade Commission, the Consumer Finance Protection Bureau, the U.S. Securities and Exchange Commission (“SEC”), the U.S. Department of Justice, the New York Department of Financial Services, the New York Department of State - Division of Consumer Protection, other U.S. state regulators, including state banking regulators, the Financial Industry Regulatory Authority, certain Congressional committees of both the U.S. Senate and House of Representatives, the United Kingdom’s Financial Conduct Authority (“FCA”), the Information Commissioner’s Office in the United Kingdom and the Office of the Privacy Commissioner of Canada. Although we are actively cooperating with these investigations and inquiries, an adverse outcome to any such investigations and inquiries could subject us to fines or other obligations, which may have an adverse effect on how we operate our business or our results of operations. In addition, we continue to cooperate with the SEC and the U.S. Attorney’s Office for the Northern District of Georgia regarding investigations into the trading activities by certain of our employees in relation to the cybersecurity incident.
TransUnion Litigation. On November 27, 2017, Trans Union LLC and TransUnion Interactive, Inc. (collectively, “TransUnion”) filed a lawsuit in the U.S. District Court for the Northern District of Illinois against Equifax Information Services LLC, Equifax Inc., and Equifax Consumer Services LLC f/k/a Equifax Consumer Services, Inc. In its lawsuit, TransUnion asserts claims for declaratory relief, breach of contract, and anticipatory repudiation of contract based on our Reciprocal Data Supply Agreement (the “Agreement”), which sets forth the pricing terms for credit monitoring supplied by the parties to each other. TransUnion seeks a declaration regarding its contractual rights under the Agreement and monetary damages. On January 26, 2018, we moved to dismiss TransUnion’s claims, and discovery in the case has been stayed until a ruling on that motion is issued. We dispute the allegations by TransUnion and intend to defend against its claims.
Securities Class Action Litigation. A consolidated putative class action lawsuit alleging violations of the federal securities laws in connection with statements regarding our cybersecurity systems and controls is pending against us and certain of our current and former officers and directors in the Northern District of Georgia. The complaints seek certification of a class of all persons who purchased or otherwise acquired Equifax securities during a set period of time and unspecified monetary damages, costs and attorneys’ fees. We dispute the allegations in these complaints and intend to defend against the claims.
Shareholder Derivative Litigation. Four putative shareholder derivative lawsuits have been commenced in the Northern District of Georgia naming certain of our current and former officers and directors as defendants and naming us as a nominal defendant. Among other things, the complaints allege claims for breaches of fiduciary duties, unjust enrichment, corporate waste, and insider selling by certain defendants. Three of the complaints also allege claims for violations of certain federal securities laws. The Complaints seek unspecified damages on behalf of the Company, plus certain equitable relief. Certain plaintiffs have filed motions seeking consolidation of the actions and appointment as lead plaintiffs. We have appointed
a committee of independent directors empowered to evaluate and respond in our best interests to the claims and related litigation demands.
It is not possible at this time to estimate the amount of loss or range of possible loss that might result from adverse judgments, settlements, penalties or other resolution of the above described proceedings and investigations based on the early stage of these proceedings and investigations, that alleged damages have not been specified, the uncertainty as to the certification of a class or classes and the size of any certified class, as applicable, and the lack of resolution on significant factual and legal issues.
Additional lawsuits and claims related to the 2017 cybersecurity incident may be asserted by or on behalf of consumers, customers, shareholders or others seeking damages or other related relief and additional inquiries from governmental agencies may be received or investigations by governmental agencies commenced.
ACCC Investigation. In March 2017, the Australian Competition and Consumer Commission (the “ACCC”) commenced an investigation to determine whether the Company has been or is engaged in unlawful acts or practices relating to advertising, marketing and sale of consumer reports, credit scores or credit monitoring products in violation of the Australian Consumer Law, which prohibits misleading or deceptive conduct and false representations. The ACCC issued a number of notices to produce documents and information. The Company expects that the ACCC will commence proceedings. If this occurs the ACCC may seek restitution, civil monetary penalties, injunctive and declaratory relief or other corrective action. The Company continues to cooperate with the ACCC in its investigation.
California Bankruptcy Litigation. In consolidated actions filed in the U.S. District Court for the Central District of California, captioned Terri N. White, et al. v. Equifax Information Services LLC, Jose Hernandez v. Equifax Information Services LLC, Kathryn L. Pike v. Equifax Information Services LLC, and Jose L. Acosta, Jr., et al. v. Trans Union LLC, et al., plaintiffs asserted that Equifax violated federal and state law (the FCRA, the California Credit Reporting Act and the California Unfair Competition Law) by failing to follow reasonable procedures to determine whether credit accounts are discharged in bankruptcy, including the method for updating the status of an account following a bankruptcy discharge. On August 20, 2008, the District Court approved a Settlement Agreement and Release providing for certain changes in the procedures used by defendants to record discharges in bankruptcy on consumer credit files. That settlement resolved claims for injunctive relief, but not plaintiffs’ claims for damages. On May 7, 2009, the District Court issued an order preliminarily approving an agreement to settle remaining class claims. The District Court subsequently deferred final approval of the settlement and required the settling parties to send a supplemental notice to those class members who filed a claim and objected to the settlement or opted out, with the cost for the re-notice to be deducted from the plaintiffs’ counsel fee award. Mailing of the supplemental notice was completed on February 15, 2011 and the deadline for this group of settling plaintiffs to provide additional documentation to support their damage claims or to opt-out of the settlement was March 31, 2011. On July 15, 2011, the District Court approved the settlement. Several objecting plaintiffs subsequently filed notices of appeal to the U.S. Court of Appeals for the Ninth Circuit, which, on April 22, 2013, issued an order vacating the settlement and remanding the case to the District Court for further proceedings. On January 21, 2014, the District Court denied the objecting plaintiffs’ motion to disqualify counsel for the settling plaintiffs and granted the motion of counsel for the settling plaintiffs to be appointed as interim lead class counsel. On March 28, 2016, the U.S. Court of Appeals for the Ninth Circuit affirmed the District Court’s lead counsel appointment. On January 9, 2017, the United States Supreme Court denied the objectors’ Petition for a Writ of Certiorari. The parties re-engaged in settlement discussions, including participation in mediations in August 2016 and November 2016, and reached an agreement to again settle the monetary claims. Settlement documents were filed with the District Court on April 14, 2017. On June 16, 2017, the Court granted preliminary approval of the proposed settlement, conditionally certified the settlement class, and appointed class counsel and administrator. A Final Fairness Hearing was held on December 11, 2017. Upon issuance of a Final Order by the Court, any appeals will be due within thirty days.
Other. Equifax has been named as a defendant in various other legal actions, including administrative claims, regulatory matters, government investigations, class actions and other litigation arising in connection with our business. Some of the legal actions include claims for substantial compensatory or punitive damages or claims for indeterminate amounts of damages. We believe we have defenses to and, where appropriate, will contest, many of these matters. Given the number of these matters, some are likely to result in adverse judgments, penalties, injunctions, fines or other relief. We may explore potential settlements before a case is taken through trial because of the uncertainty and risks inherent in the litigation process.
For information regarding our accounting for legal contingencies, see Note 6 of the Notes to Consolidated Financial Statements in this Form 10-K.
Previous: Item 2. PROPERTIES · Next: Item 4. MINE SAFETY DISCLOSURES