WASHINGTON - Members of Congress showed bewilderment Wednesday that credit reporting company Equifax (EFX), under siege after a data breach affecting more than 145 million people, has received a $7.25 million contract with the IRS to provide taxpayer and personal identity verification services.
"Why in the world should you get a no-bid contract right now?" Sen. Ben Sasse, R-Nebraska, asked former Equifax CEO Richard Smith at a Senate Banking, Housing and Urban Affairs Committee hearing.
Sasse's indignation was soon topped by Sen. John Kennedy, R-Louisiana, who said, "You realize, to many Americans right now, that looks like we're giving Lindsay Lohan the keys to the mini-bar."
"I understand your point," Smith said in response to Kennedy's observation, a reference to the actress who has struggled with drugs and alcohol.
Smith testified at the second of four congressional hearings this week in which lawmakers demanded to know how the breach happened and what the company was doing to make things right for consumers. Hackers stole Social Security numbers, birth dates and addresses, and in some instances driver's license numbers.
In a statement released Tuesday, Oregon Democratic Represtative Earl Blumenauer explained his reaction when he heard about Equifax's IRS contract: "I was initially under the impression that my staff was sharing a copy of the Onion, until I realized this story was, in fact, true."
Smith said he didn't know many details about the IRS contract, but he explained that it was for work Equifax has done in the past for the tax agency, and he thought the contract was being renewed. He also said he believed the contract was "to prevent fraudulent access to the IRS."
The contract says Equifax was the only company capable of providing the services, and it was deemed a "critical" service that couldn't lapse.
Sen. Heidi Heitkamp, D-North Dakota, said Equifax forced the IRS to take the contract for another year after issuing a protest. She called on Smith to tell the IRS that it's fine to take the contract somewhere else.
The IRS issued a statement that said Equifax advised the agency that no IRS data was involved in the breach. The statement confirmed that the renewal was awarded to Equifax to prevent a lapse in service.
"Following an internal review and an on-site visit with Equifax, the IRS believes the service Equifax provided does not pose a risk to IRS data or systems," the statement read.
Smith was Equifax's CEO for a dozen years. He resigned after the breach was announced. No current Equifax employees testified at the hearing. Lawmakers accused Equifax of being too lax about securing consumer data, noting that there had been previous breaches over the past four years.
Ohio Sen. Sherrod Brown, the committee's top Democrat, said consumers should have expected their most private information would have state-of-the-art protections.
"A gold mine for hackers should be a digital Fort Knox when it comes to security," Brown said.
Sen. Elizabeth Warren, D-Massachusetts, said Equifax didn't have enough incentive to ensure consumer data was secure. She said the breach means consumers will spend the rest of their lives worrying about identity theft and businesses will lose money to thieves, but Equifax itself will come out of the crisis just fine.
Warren has called for changes in how credit reporting agencies operate. She said consumers should decide who gets their financial data, not companies such as Equifax. She is also calling for stiffer penalties when breaches do occur.
"When companies like Equifax mess up, senior executives like you should be held personally accountable, and the company should pay mandatory and severe financial penalties for every consumer record that's stolen," Warren said.
"We've got to change this industry before more consumers get hurt," she said.
Smith told the lawmakers that credit reporting companies like Equifax provide a valuable service that allows consumers to get access to credit. "We're a vital part to the global economy," Smith said.
Smith said he agreed that consumers should be able to determine who gets access to their information and that the company was unveiling a new product in January that would allow customers while online to lock and unlock their credit reports any time they wanted. He encouraged competing credit reporting companies to offer the service to all consumers on one website.
"It would be a paradigm shift for the consumer," Smith said.
Meanwhile, Equifax is under investigation by the Department of Justice, Federal Trade Commission, Securities and Exchange Commission and Consumer Federal Protection Bureau, as well as by more than 40 state attorneys general.