Letter to Dean Stoecker, Chairman and Chief Executive Office of Alteryx, Inc. - Lujan and Schakowsky Push Data Analytics Company for Answers Following Significant Data Breach

Letter

Date: Jan. 12, 2018
Location: Washington, DC

Dear Mr. Stoecker:

We are writing to request a briefing on the recent disclosure that Alteryx, Inc. exposed personal information on almost every person in the United States by failing to secure online files containing hundreds of different categories of consumer data. As a data analytics and marketing company, Alteryx collects and sells detailed information on consumers' identities, finances, habits, preferences, and other attributes.[1]

On December 20, 2017, Alteryx revealed that the company had accidentally exposed nonpublic marketing data on 123 million U.S. households from the consumer reporting agency Experian.[2] The unsecured files also included publically available data from the U.S. Census Bureau.[3] Alteryx stored the files online using Amazon Web Services (AWS) and left them accessible to anyone with a free AWS account.[4]

Alteryx has since removed the files from AWS, and has stated that the files did not contain names, Social Security numbers, passwords, or credit card numbers.[5] However, 248 other types of personal information were exposed, including phone numbers, addresses, ethnicity, detailed financial and housing information, and information on children.[6] Security researchers have warned that such data can easily be used to identify people when cross-referenced with public records and other available information.[7]

Companies in the consumer data industry collect and sell vast quantities of personal information that, if exposed, can leave consumers vulnerable to fraud, identity theft, and other abuses. The Subcommittee on Digital Commerce and Consumer Protection has a longstanding interest in safeguarding the privacy and security of consumer information. We therefore request a briefing on this incident with our staff and Committee staff before January 31, 2018. Please be prepared to discuss the following questions:

1. News reports have indicated that the exposed files contained a mix of public and private information from Experian, the U.S. Census Bureau, and other sources. What specific categories of consumer information were exposed, and what are the sources of the information?

2. How long did Alteryx leave the files exposed on AWS? When and how did Alteryx discover that the files were exposed? When did Alteryx remove the exposed files?

3. Does Alteryx know who or how many people accessed the exposed files while they were publically available?

4. What were Alteryx's internal data security policies at the time of this incident? Has the company conducted an investigation to determine how and why the incident occurred? What were the results of any investigation?

5. Is Alteryx changing its privacy and data security policies in light of this incident?

6. Did Experian, or any other company from whom Alteryx obtained consumer data, require that Alteryx have any privacy or data security standards before selling them the information contained in the exposed files?

7. Is Alteryx offering or planning to offer any type of post-breach consumer protection service to consumers?

To schedule the briefing, please contact Graham Mason with Congressman Ben Ray Luján at (202) 225-6190 and Matt Hayward with Ranking Member Jan Schakowsky at (202) 225-2111. Thank you for your prompt attention to this matter.

Sincerely,


Source
arrow_upward