Former employees say Experian's efforts to improve security slipped after the departure of CIO John Finch
Brian Krebs / Krebs on Security : Tweets: @futurecrimes , @hypatiadotca , @ekoivune , @dangillmor , @ncweaver and @kashhill Tweets: Marc Goodman / @futurecrimes : At @Experian, culture of poor morale in INFOSEC department leads to greater risks for all customers. #TMOHACK http://krebsonsecurity.com/... Leigh Honeywell / @hypatiadotca : Great article from @briankrebs about the security culture at Experian leading up to the T-Mo/Experian breach: http://krebsonsecurity.com/... Erka Koivunen / @ekoivune : “Experian..fixated on acquiring..data broker and analytics tech [while failing] to improve security.” @briankrebs http://krebsonsecurity.com/... Dan Gillmor / @dangillmor : The dogged @briankrebs explains that Experian's lousy security is inevitable given the way company is run: http://krebsonsecurity.com/... Nicholas Weaver / @ncweaver : Experian really IS a disaster area: ex division CISO willing to go on the record to @briankrebs http://krebsonsecurity.com/... Kashmir Hill / @kashhill : Experian loves amassing data about you, but is not as keen on securing it, reports @briankrebs http://krebsonsecurity.com/...
Context & Ripple Effects
Brian Krebs reports that inside Experian, the departure of CIO John Finch marked the point where security improvement efforts stalled — former employees describe an INFOSEC department with poor morale, at exactly the moment Experian was pushing to acquire more data-brokerage and analytics capability than it could secure. The backdrop is the T-Mobile/Experian breach, which exposed customer records processed through Experian's own systems.
The report reads differently now than it did in 2015: later coverage shows the same bureau struggling with hijacked accounts and PIN-reset flaws in its authentication flow years afterward, while Equifax — whose data-gathering strategy amplified the blast radius of its own breach — became the sector's cautionary case. The through-line is bureaus selling safety while under-investing in it.
First-order effects
- Experian's INFOSEC staff are working without executive-level security sponsorship after Finch's exit, and customers whose data sat in Experian's breached systems bear the immediate exposure risk.
- Krebs' sourcing puts Experian on the record publicly: a company whose brand rests on trust in handling sensitive credit data is being described by its own former employees as deprioritizing security.
Second-order effects
- Peer bureaus face the same scrutiny template Krebs applied to Experian — Equifax was subsequently shown to have ignored a researcher's warning months before its breach, suggesting the insider-account genre becomes standard crisis coverage for the whole sector.
- Breach fallout feeds the bureaus' adjacent revenue line: Experian and rivals market identity-protection services built partly on fear of the very exposures their own lapses create, converting security failures into upsell demand.
Third-order effects
- If the pattern holds — acquisition-driven data accumulation outpacing security investment — credit bureaus consolidate into high-value targets for state-sponsored attackers, as the eventual attribution of the Equifax hack to Chinese state hackers demonstrated.
- Structurally, the sector's incentive problem deepens: breaches impose costs on consumers rather than primarily on the bureau, weakening the market signal that would otherwise force security spending, and inviting regulatory intervention as the only counterweight.
The trend: Consumer-data aggregators keep growing their holdings faster than their defenses, turning credit bureaus into recurring breach targets whose security failures become marketing fodder for the same companies.