A Dark Vector Cognition product

Item 3. LEGAL PROCEEDINGS

9K characters. Original on sec.gov · Markdown

Item 3. LEGAL PROCEEDINGS

Litigation and Investigations related to the 2017 Cybersecurity Incident

In fiscal 2017, we experienced a cybersecurity incident following a criminal attack on our systems that involved the theft of certain personally identifiable information of U.S., Canadian and U.K. consumers. Following the 2017 cybersecurity incident, hundreds of class actions and other lawsuits were filed against us typically alleging harm from the incident and seeking various remedies, including monetary and injunctive relief. We were also subject to investigations and inquiries by federal, state and foreign governmental agencies and officials regarding the 2017 cybersecurity incident and related matters. Most of these lawsuits and government investigations have concluded or been resolved, including pursuant to the settlement agreements described below, while others remain ongoing. The Company’s participation in these settlements does not constitute an admission by the Company of any fault or liability, and the Company does not admit fault or liability.

Consumer Settlement

On July 19, 2019 and July 22, 2019, we entered into multiple agreements that resolve the U.S. consolidated consumer class action cases, captioned In re: Equifax, Inc. Customer Data Security Breach Litigation, MDL No. 2800 (the “U.S. Consumer MDL Litigation”), and the investigations of the FTC, the CFPB, the Attorneys General of 48 states, the District of Columbia and Puerto Rico (the "MSAG Group") and the NYDFS (collectively, the “Consumer Settlement”). Under the terms of the Consumer Settlement, the Company will contribute $380.5 million to a non-reversionary settlement fund (the “Consumer Restitution Fund”) to provide restitution for U.S. consumers identified by the Company whose personal information was compromised as a result of the 2017 cybersecurity incident as well as to pay reasonable attorneys’ fees and reasonable costs and expenses for the plaintiffs’ counsel in the U.S. Consumer MDL Litigation (not to exceed $80.5 million), settlement administration costs and notice costs. The Company has agreed to contribute up to an additional $125.0 million to the Consumer Restitution Fund to cover certain unreimbursed costs and expenditures incurred by affected U.S. consumers in the event the $380.5 million in the Consumer Restitution Fund is exhausted. The Company also agreed to various business practice commitments related to consumer assistance and its information security program, including conducting third party assessments of its information security program.

On January 13, 2020, the Northern District of Georgia, the U.S. District Court overseeing centralized pre-trial proceedings for the U.S. Consumer MDL Litigation and numerous other federal court actions relating to the 2017 cybersecurity incident (the “MDL Court”), entered an order granting final approval of the settlement in connection with the U.S. Consumer MDL Litigation. The MDL Court entered an amended order granting final approval of the settlement on March 17, 2020. Several objectors have appealed the final approval order. Until the appeals are finally adjudicated or dismissed and the settlement becomes final in accordance with its terms, we can provide no assurance that the U.S. Consumer MDL Litigation will be resolved as contemplated by the settlement agreement. If the Court’s order approving the settlement agreement was overturned by an appellate court and not cured in accordance with the terms of the consent orders with the FTC and CFPB, the consent orders with the FTC, CFPB and MSAG Group would remain in place and the Consumer Restitution Fund would be administered by the FTC. In that event, there is a risk that we would not be able to settle the U.S. Consumer MDL Litigation on acceptable terms or at all, which could have a material adverse effect on our financial condition.

Other Settlements

Financial Institutions MDL Class Action. On May 15, 2020, the Company entered into a settlement agreement to resolve the consolidated financial institutions class action cases pending before the MDL Court (the “Financial Institutions MDL Litigation”). Under the settlement, the Company agreed to pay for valid claims submitted by class members up to a maximum amount, reasonable settlement administration and notice costs, and reasonable attorneys’ fees and expenses. The Company also agreed to adopt and/or maintain certain business practices related to its information security program. The court granted final approval of the settlement on October 22, 2020.

Other Matters

We face other lawsuits and government investigations related to the 2017 cybersecurity incident that have not yet been concluded or resolved. These ongoing matters may result in judgments, fines or penalties, settlements or other relief. We dispute the allegations in the remaining lawsuits and intend to defend against such claims. Set forth below are descriptions of the main categories of these matters.

Georgia State Court Consumer Class Actions. Four putative class actions arising from the 2017 cybersecurity incident were filed against us in Fulton County Superior Court and Fulton County State Court in Georgia based on similar allegations

and theories as alleged in the U.S. Consumer MDL Litigation and seek monetary damages, injunctive relief and other related relief on behalf of Georgia citizens. These cases were transferred to a single judge in the Fulton County Business Court and three of the cases were consolidated into a single action. On July 27, 2018, the Fulton County Business Court granted the Company’s motion to stay the remaining single case, and on August 17, 2018, the Fulton County Business Court granted the Company’s motion to stay the consolidated case. These cases remain stayed pending final resolution of the U.S. Consumer MDL Litigation.

Canadian Class Actions. Five putative Canadian class actions, four of which are on behalf of a national class of approximately 19,000 Canadian consumers, are pending against us in Ontario, British Columbia and Alberta. Each of the proposed Canadian class actions asserts a number of common law and statutory claims seeking monetary damages and other related relief in connection with the 2017 cybersecurity incident. In addition to seeking class certification on behalf of the approximately 19,000 Canadian consumers whose personal information was allegedly impacted by the 2017 cybersecurity incident, in some cases, plaintiffs also seek class certification on behalf of a larger group of Canadian consumers who had contracts for subscription products with Equifax around the time of the incident or earlier and were not impacted by the incident.

On December 13, 2019, the court in Ontario granted certification of a nationwide class that includes all impacted Canadians as well as Canadians who had subscription products with Equifax between March 7, 2017 and July 30, 2017 who were not impacted by the incident. Our motion for leave to appeal this decision was granted in part, and our appeal is now pending. All remaining purported class actions are at preliminary stages or stayed.

Government Investigations. We have cooperated with federal, state and foreign governmental agencies and officials investigating or otherwise seeking information, testimony and/or documents, regarding the 2017 cybersecurity incident and related matters. Except as described below, these investigations have been resolved as discussed in prior filings or there has been no further activity.

The U.K.’s Financial Conduct Authority (“FCA”) opened an enforcement investigation against our U.K. subsidiary, Equifax Limited, in October 2017. The investigation by the FCA has involved a number of information requirements and interviews. We continue to respond to the information requirements and are cooperating with the investigation.

Other

Equifax has been named as a defendant in various other legal actions, including administrative claims, regulatory matters, government investigations, class actions and other litigation arising in connection with our business. Some of the legal actions include claims for substantial compensatory or punitive damages or claims for indeterminate amounts of damages. We believe we have defenses to and, where appropriate, will contest, many of these matters. Given the number of these matters, some are likely to result in adverse judgments, penalties, injunctions, fines or other relief. We may explore potential settlements before a case is taken through trial because of the uncertainty and risks inherent in the litigation process.

For information regarding our accounting for legal contingencies, see Note 6 of the Notes to Consolidated Financial Statements in Item 8 of this report.

Previous: Item 2. PROPERTIES · Next: Item 4. MINE SAFETY DISCLOSURES