/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Former employees say Experian's efforts to improve security slipped after the departure of CIO John Finch

Brian Krebs / Krebs on Security : Tweets: @futurecrimes , @hypatiadotca , @ekoivune , @dangillmor , @ncweaver and @kashhill Tweets: Marc Goodman / @futurecrimes : At @Experian, culture of poor morale in INFOSEC department leads to greater risks for all customers. #TMOHACK http://krebsonsecurity.com/... Leigh Honeywell / @hypatiadotca : Great article from @briankrebs about the security culture at Experian leading up to the T-Mo/Experian breach: http://krebsonsecurity.com/... Erka Koivunen / @ekoivune : “Experian..fixated on acquiring..data broker and analytics tech [while failing] to improve security.” @briankrebs http://krebsonsecurity.com/... Dan Gillmor / @dangillmor : The dogged @briankrebs explains that Experian's lousy security is inevitable given the way company is run: http://krebsonsecurity.com/... Nicholas Weaver / @ncweaver : Experian really IS a disaster area: ex division CISO willing to go on the record to @briankrebs http://krebsonsecurity.com/... Kashmir Hill / @kashhill : Experian loves amassing data about you, but is not as keen on securing it, reports @briankrebs http://krebsonsecurity.com/...

Krebs on Security Brian Krebs

Context & Ripple Effects

Brian Krebs reports that inside Experian, the departure of CIO John Finch marked the point where security improvement efforts stalled — former employees describe an INFOSEC department with poor morale, at exactly the moment Experian was pushing to acquire more data-brokerage and analytics capability than it could secure. The backdrop is the T-Mobile/Experian breach, which exposed customer records processed through Experian's own systems.

The report reads differently now than it did in 2015: later coverage shows the same bureau struggling with hijacked accounts and PIN-reset flaws in its authentication flow years afterward, while Equifax — whose data-gathering strategy amplified the blast radius of its own breach — became the sector's cautionary case. The through-line is bureaus selling safety while under-investing in it.

First-order effects

  • Experian's INFOSEC staff are working without executive-level security sponsorship after Finch's exit, and customers whose data sat in Experian's breached systems bear the immediate exposure risk.
  • Krebs' sourcing puts Experian on the record publicly: a company whose brand rests on trust in handling sensitive credit data is being described by its own former employees as deprioritizing security.

Second-order effects

  • Peer bureaus face the same scrutiny template Krebs applied to Experian — Equifax was subsequently shown to have ignored a researcher's warning months before its breach, suggesting the insider-account genre becomes standard crisis coverage for the whole sector.
  • Breach fallout feeds the bureaus' adjacent revenue line: Experian and rivals market identity-protection services built partly on fear of the very exposures their own lapses create, converting security failures into upsell demand.

Third-order effects

  • If the pattern holds — acquisition-driven data accumulation outpacing security investment — credit bureaus consolidate into high-value targets for state-sponsored attackers, as the eventual attribution of the Equifax hack to Chinese state hackers demonstrated.
  • Structurally, the sector's incentive problem deepens: breaches impose costs on consumers rather than primarily on the bureau, weakening the market signal that would otherwise force security spending, and inviting regulatory intervention as the only counterweight.

The trend: Consumer-data aggregators keep growing their holdings faster than their defenses, turning credit bureaus into recurring breach targets whose security failures become marketing fodder for the same companies.