(Bloomberg) -- Gee thanks, Gus.
Gus isn't a real person, but it's the pseudonym Senator Al Franken assigned to the Equifax Inc. employee who holds a lot of the blame for the theft of 145.5 million Americans' personal data.
Former Chief Executive Officer Richard Smith told Franken and other senators Wednesday that Equifax was breached largely because of a breakdown in communication within the company. Gus and his team were responsible for telling the techies that a software vulnerability needed to be fixed. It never happened.
Also Read | Layoffs Are Rising In Tech, But These Skills Are Helping People Unlock Better Pay
“Why is the security of 145 million people all in the hands of one guy?" Franken, a Minnesota Democrat, asked Smith at a Senate Judiciary Subcommittee hearing. “Why is it all up to Gus?"
Former Employee
If Smith knows Gus's real name, he kept it to himself. Smith did share a key tidbit about the employee, though: he indicated the person is no longer at the Atlanta-based company.
At the hearing, Smith reiterated the chain of events that led up to the intrusion.
The Department of Homeland Security identified a software vulnerability in March and alerted various companies that were using that software. Equifax then issued an internal notification requesting that the code be upgraded, with the company's security department mandating that any weakness be patched within 48 hours. We now know the program was never repaired.
Many Missteps
But Gus may not be entirely at fault. Smith said it's possible “this one guy” didn't know all of Equifax's various business portals were using the faulty software. Later security scans didn't detect the vulnerability either.
“I am not certain that the person who is responsible for communicating that the patch needed to be applied” knew “the software was applied,” the ex-CEO said.
Equifax made more missteps after it publicly disclosed the hack Sept. 7.
A customer service representative tasked with responding to customers' Tweets sent out incorrect links to the website the company created to help consumers sign up for credit monitoring. Instead, that person was tweeting out links to a phishing website with a similar name. That customer service representative is no longer with the company, Smith said Wednesday.
To contact the reporters on this story: Elizabeth Dexheimer in Washington at edexheimer@bloomberg.net, Jenny Surane in New York at jsurane4@bloomberg.net.
To contact the editors responsible for this story: Jesse Westbrook at jwestbrook1@bloomberg.net, Steven Crabill
Essential Business Intelligence, Sharp Market Insights, Practical Personal Finance Advice, Daily Fuel, Gold and Silver Prices and Latest Stories — On NDTV Profit.