Showing posts with label certegy. Show all posts
Showing posts with label certegy. Show all posts

Friday, August 17, 2007

Class action law suit filed against Certegy for data breach

Data breaches are likely to become costly to organizations who fail to protect their information. The TJX data breach (45 million people and counting compromised) has inspired several legal actions in both the United States and Canada.

Now a similar action is being brought against Certegy, a check verification company, who had an insider sell information to a still (as far as I know) undisclosed data broker.

An August 15th press release announced:

The law firm of Girard Gibbs LLP (http://www.girardgibbs.com/) has filed a class action complaint on behalf of approximately 8.5 million consumers nationwide whose financial and personal data was stolen by an employee of Certegy Check Services, Inc. and Fidelity National Information Services, Inc (NYSE: FIS) and released to unauthorized third parties. The complaint alleges that a senior database administrator misappropriated the confidential information of millions of consumers and then sold the data to direct marketing firms and data brokers who may have resold it to others.

Certegy and FIS had a duty to safeguard the confidential data of consumers from any breach, including that of their employees. Once the internal breach became known, it should have been communicated to the public in a timely and adequate manner,” said Eric Gibbs, one of the attorneys for the plaintiff. “The failure by these companies to make the internal data breach immediately known exposed consumers to direct marketing campaigns and the risk of unauthorized use of their bank accounts and identity theft.”
This case is interesting because it involves customer information that was obtained at merchants, who used the service to verify whether a person's check, or sometimes payment card was good.

I wrote a couple of posts about Certegy, which received a lot of comments. One comment (in my opinion) by a "Risk Manager" opened up another can of worms:

I think there is a bigger issue here that Certegy does not "own" the data that was stolen but in fact it is records of Certegy customers like businesses that contract Certegy for check-cashing services. I would ask Certegy to confirm what they store on their systems, how long they store it and why bank account and credit card numbers are stored AND investigate if Certegy violated any Visa/PCI mandates.

This seems to be a reasonable question, especially in light of some of the more high profile data breaches, we've recently seen. However in this instance, since all it takes is one person (who has access) to compromise information, it probably wouldn't have made much difference.

The reality is that Certegy sells the fact that they store a lot of information on people to merchants. Without this information, they wouldn't have a service to sell.

Nonetheless, the statement does warrant consideration as to how well third party databases are protected, especially when they contain detailed personal and financial information?

I'm not sure why the data broker, who bought the information hasn't been identified? They are responsible for buying and selling information all the time. Information is worth money and is being sold (some believe haphazardly) all the time.

Recently, it was disclosed that a data broker sold lists targeting elderly gamblers to sweepstakes (lottery) scammers. New York Times article, here.

Current laws enable financial institutions to sell your information, unless you go through a pretty complicated process of opting-out. They are required by law to notify you of your rights, but these are often sent out via snail mail and called "privacy notices." I've often made the mistake of thinking they were junk mail and shredded them.

They don't make it easy for the average person to protect their information.

I wonder how much personal information is sold to people that shouldn't be getting it? Even if we manage to opt-out today, how much of our information is already stored on a database somewhere?

Since the people enabling information to be compromised are making billions of dollars by selling it -- perhaps more of these lawsuits are one way to hold them accountable and bring some sanity to what is becoming a situation -- which seems to get worse all the time?

Of course, more laws to protect consumers are needed, also!

As I stated earlier, this is going to be interesting. I don't know where it will go, but maybe this is a signal to the people data mining our information to wake up and smell the coffee?

If they don't, they might end up dealing with a lot of litigation, which is always very costly.

It also might put them out of business. Dark Reading did an article this week about another third party vendor Verus, who folded after it was disclosed that they lost a lot of people's information from several hospitals. The point of compromise in this situation was the failure of some IT people to leave a firewall up when transferring information between servers.

Here are my two previous posts on the Certegy breach:

Not to worry, check processing company (Certegy) believes the 2.3 million stolen records will not be used for fraud!

Certegy reveals their data breach is a lot larger than originally reported

Saturday, July 28, 2007

Certegy reveals their data breach is a lot larger than originally reported

Earlier this month, I blogged about the Certegy data breach, where a not very HONEST employee got caught selling information to an unidentified data-broker. Certegy was quick to assure the public that none of this information would be used to commit fraud because it was being used by "legitimate marketing firms."

Now the number of records (people compromised) has risen significantly after Certegy filed a report with the Securities and Exchange Commission.

The Tampa Bay Business Journal Reports:

An ongoing investigation has determined that about 8.5 million consumer records were stolen, according to a July 25 Securities and Exchange Commission filing by Fidelity National Information Services Inc. (NYSE: FIS), the Jacksonville-based parent company of St. Petersburg-based Certegy.
According to Fidelity, Certegy's parent company the investigation is continuing and this number could grow.

Florida Attorney General Bill McCollom listed some useful information for victims in a press release, which said:

For more information, consumers may call Certegy at 866-498-9916 or may visit their website at http://www.certegy.com. Affected consumers are encouraged to take the precautionary steps outlined in the Certegy letter, including obtaining a free fraud alert from one of the credit reporting agencies. Furthermore, if consumers believe at any time they are victims of identity theft, they should report this to the police and request that the national credit bureaus place a fraud alert on their credit reports. Consumers should also notify banks and creditors involved of questionable charges or accounts, keep records of all telephone calls and follow up in writing with credit bureaus, banks and creditors.

If you received a letter from Certegy and you continue to receive marketing calls that you suspect result from this data breach, please report this activity to the Attorney General’s Citizens Services Hotline at 1-866-9-No SCAM (1-866-966-7226). Additional information about protecting yourself from identity theft is available online at http://www.myfloridalegal.com/identitytheft.


I've received a lot of comments on my original post, including some (anonymous) claiming their information was used for fraud. Unfortunately, I cannot verify this information, but someone with the e-mail address LPLong@Yahoo.com claims to be collecting victims to file a class action law suit.

My original post with comments, here.

Press release from Florida Attorney General (Bill McCollom), here.

Note this is probably the right place to verify information, if you receive a letter. If you believe you are fraud victim based on the Certegy breach, I would let them know about it, also.

Tampa Bay Business Journal article, here.

Wednesday, July 04, 2007

Not to worry, check processing company (Certegy) believes the 2.3 million stolen records will not be used for fraud!

Large data breaches are becoming a VERY frequent news event! This time only 2.3 million records were stolen, a mere fraction of the amount (45 million plus) TJX lost. In this instance, we are told we have nothing to fear because the information was sold to a data broker.

Ron Word of the AP (courtesy of the Washington Post) reports:

Fidelity National Information Services, a financial processing company, said yesterday that a worker at one of its subsidiaries stole 2.3 million consumer records containing credit card, bank account and other personal information.

This occurred at one of their subsidiaries, Certegy Check Services.

According to the article:


About 2.2 million records stolen from Certegy contained bank account information and 99,000 contained credit card information, company officials said.

Since Certegy verifies check transactions, this probably means a lot of checking account information in addition to some credit and personal information. From a financial crimes perspective, this information could be used to commit a lot of identity theft, check and credit card fraud.

The company claims the information was sold to data brokers, who sold it to direct marketers. Their president, Renz Nichols, "believes" this is the extent of the damage.

Not sure, if I can "believe" that no one is at risk. The last time I checked, identity thieves normally shy away from revealing exactly, who they intend to compromise next. It's bad for business. Besides that, is this based on the word of someone, who stole the information and sold it in the first place?

Interestingly enough, the data broker is unnamed at this point. The AP article does say they are claiming they didn't know the information was stolen. I wonder how this data broker verifies the information they get, and who they are getting it from?

Data brokers and credit bureaus sell information all the time. Recently, a data broker (InfoUSA) was caught selling direct marketing information to spammers, who commit lottery fraud schemes.

The sad thing is that once the information starts getting sold, it becomes available to more and more insiders, who might sell it to the wrong person, assuming it hasn't been already.

And there is so much information to be sold, no one is ever sure exactly where it came from. Criminals are even selling it via the Internet to other criminals.

AP Story (courtesy of the Washington Post), here.

Attrition.org is tracking data breaches, here. The amount of them that happen is pretty scary!

I've written a lot of about how data brokers make billions buying and selling our information, which can later used against us, here.

They don't believe they are enabling a worldwide problem, either.

At least that's what I keep hearing, whenever a new data breach is announced.