{"database": "press", "table": "releases", "rows": [["https://www.thune.senate.gov//public/index.cfm/press-releases?ContentRecord_id=02FFCCA1-FBAC-4D72-A75F-560FEE19B010", "Thune Presses Current and Former Leaders of Equifax and Yahoo! in Commerce Hearing Examining Data Breaches", "2017-11-08", "2017", "2017-11", "Republican", "House", "SD", "John Thune", "T000250", "www.thune.senate.gov", null, null, "legacy", "WASHINGTON\u00a0\u2014\u00a0\r\n\t\t\r\n\t\t\r\n\t\tU.S. Sen. John Thune (R-S.D.), chairman of the Senate Committee on Commerce, Science, and Transportation, today convened a hearing titled, \u201cProtecting Consumers in the Era of Major Data Breaches.\u201d The hearing featured testimony from current and former officials who worked on Yahoo!\u2019s response to the 2013 data breach, which affected all 3 billion user accounts and was just revealed last month. It also featured current and former CEOs of Equifax, which suffered a 2017 breach that reportedly affected approximately 145 million individuals and exposed sensitive personal and financial information.\r\nDuring the hearing, Thune questioned Yahoo!\u2019s former CEO Marissa Mayer on Yahoo!\u2019s security collapses and its failure to effectively respond to those collapses in a timely matter. Thune also pressed Equifax\u2019s former CEO Richard Smith and interim CEO Paulino Barros on Equifax\u2019s known security vulnerabilities that led to its recent data breach and how the company is currently addressing these issues.\u00a0 \u00a0\r\nThune\u2019s opening statement (as prepared for delivery):\r\n\u201cNow that our executive session is complete, we turn to the issue of data breaches.\u00a0\r\n\u201cData breach is not a new issue for the Committee to explore.\u00a0\r\n\u201cIn fact, the Committee has been focused on the consumer impact of data breaches since before I was elected to the U.S. Senate.\r\n\u201cThe September 2004 ChoicePoint breach, what many consider to be the first high-profile data breach of the modern era, prompted a number of investigations from this Committee, the FTC, and federal and state authorities.\u00a0\r\n\u201cFor those that don\u2019t remember, ChoicePoint was a data aggregation company originally created by Equifax, who as fate would have it, is represented here today.\u00a0\r\n\u201cIn terms of the trajectory of congressional inquiry into major data breaches, you might say we have come full circle.\r\n\u201cIn the intervening years, Congress, and this Committee in particular, have paid close attention to data breaches big and small.\r\n\u201cIn addition, the Committee has entertained a variety of proposals to strengthen data security requirements for companies across the board, as well as to impose federal requirements for affected companies to notify their consumers following the discovery of a breach.\u00a0 \u00a0\r\n\u201cSadly, we are truly in the era of major data breaches.\u00a0\r\n\u201cThese include the large-scale breaches at Equifax and Yahoo! that we are examining today.\u00a0\r\n\u201cWhile the Yahoo! breaches are larger in terms of affected consumers, the Equifax breach is potentially much more severe given the sensitive nature of the consumer information compromised.\u00a0\r\n\u201cIn fact, I have heard from many constituents in South Dakota who are concerned about the lasting effects of the Equifax breach.\u00a0\r\n\u201cI have also heard complaints that it is difficult to set up a credit freeze, and questions about whether credit monitoring is an effective tool to prevent identity theft.\r\n\u201cThe Equifax breach reportedly exposed the sensitive personal data of about 145.5 million U.S. consumers, including their names, social security numbers, birth dates, addresses, and in some cases, driver\u2019s license numbers.\u00a0\r\n\u201cAlso exposed were the credit card numbers for more than 200,000 U.S. consumers and dispute documents containing personal identifying information for more than 180,000 U.S. consumers.\u00a0\r\n\u201cToday, Equifax will have an opportunity to provide an update regarding the breach, as well as its much-criticized efforts to mitigate the harm and prevent anything like this from happening again.\u00a0\r\n\u201cThe Yahoo! breach we will discuss today\u00a0 compromised over 3 billion user accounts and followed a prior breach in which hackers stole similar types of information from at least 500 million users.\u00a0\r\n\u201cThe compromised data included names, telephone numbers, dates of birth, partial passwords, unencrypted security questions and answers, backup e-mail addresses, and employment information.\u00a0\r\n\u201cThe 3 billion figure constitutes the entirety of the Yahoo! Mail and other Yahoo!-owned accounts at the time of the breach.\u00a0\r\n\u201cToday Yahoo! representatives will have an opportunity to provide an update regarding these breaches as well as efforts to mitigate the harm and ensure the security of consumer data going forward.\u00a0\r\n\u201cThe massive data breaches at Equifax and Yahoo! illustrate quite dramatically that our nation continues to face constantly evolving cyber threats to our personal data.\u00a0\r\n\u201cCompanies that collect and store personal data on American citizens must step up to provide adequate cybersecurity.\u00a0 And there should be consequences if they fail to do so.\u00a0\r\n\u201cThe Committee has made cybersecurity a priority, and I am hopeful that today\u2019s hearing will help the Committee to better understand these challenges as it considers legislation to address data breach notification and data security issues.\u00a0\r\n\u201cWhen there is risk of real harm stemming from a breach, we must make sure that consumers have the information they need to protect themselves.\u00a0\r\n\u201cThat is why I support a uniform Federal breach notification standard to replace the patchwork of laws in 48 states, in addition to the District of Columbia and three other territories.\r\n\u201cA single Federal standard would ensure all consumers are treated the same with regard to notification of data breaches that might cause them harm.\u00a0\r\n\u201cSuch a standard would also provide consistency and certainty regarding timely notification practices, benefiting both consumers and businesses.\r\n\u201cIn order to ensure that businesses secure information appropriately, I have also advocated for uniform, reasonable security requirements to protect consumer data, based on the size and scope of the company and the sensitivity of the information.\u00a0\r\n\u201cHowever, in this regard, the facts of the Equifax breach are particularly troubling.\u00a0\r\n\u201cAs a credit bureau, Equifax was already subject to the Safeguards Rule under the Gramm-Leach-Bliley Act, which is considered to be a stringent regulation.\u00a0\r\n\u201cNevertheless, the Equifax breach occurred and its implications on American consumers appear dire.\r\n\u201cEnhancing security and protecting the personal data of American consumers will continue to be a priority for this Committee.\u00a0\r\n\u201cI want to thank all of the witnesses for appearing here today.\u00a0 I look forward to hearing your testimony.\u00a0\r\n\u201cI will now turn to Senator Nelson for his opening remarks.\u201d", 1, "2026-03-30T12:14:52Z", "2026-03-30T12:14:52Z"]], "columns": ["url", "title", "date", "year", "month", "party", "chamber", "state", "member_name", "bioguide_id", "domain", "scraper", "source", "date_source", "text", "has_text", "collected_at", "updated_at"], "primary_keys": ["url"], "primary_key_values": ["https://www.thune.senate.gov//public/index.cfm/press-releases?ContentRecord_id=02FFCCA1-FBAC-4D72-A75F-560FEE19B010"], "units": {}, "query_ms": 0.802536029368639, "source": "dwillis/congress-press", "source_url": "https://github.com/dwillis/congress-press", "license": "MIT", "license_url": "https://github.com/dwillis/congress-press/blob/main/LICENSE"}