Showing posts with label class action law suit. Show all posts
Showing posts with label class action law suit. Show all posts

Sunday, May 25, 2008

Lifelock's identity theft protection saga racks up 339 articles in Google!

Todd Davis, Lifelock's flamboyant CEO, who flashes his social security in public to sell identity theft protection made Yahoo's top five stories of the week. When I checked Google News, there were no less than 339 articles covering the woes of Lifelock and it's CEO.

Lifelock has been mired in controversy since it was revealed in the New Phoenix Times that one of his co-founders (Robert Maynard) wasn't being truthful about being an identity theft victim and was suspected of being a identity thief, himself.

I covered this part of the Lifelock saga in a post called, "Is LifeLock an identity theft protection service people can trust?"

Maynard stepped down from his position as co-founder, but continued to maintain a 10 percent interest in the company.

A short while thereafter, it was revealed that Todd Davis was himself a victim of identity theft. Instead of letting the authorities do their job, Davis took it upon himself to send out a PI (and film crew) to get a pre-written confession from the scoundrel. The end result was that the authorities dropped the case.

Meanwhile, Lifelock seemed to flourish and obtained a lot of investment capital to drive their aggressive marketing campaign. Everyone from Radio icons to bloggers have been paid to endorse their services.

The bad publicity even led to speculation that an organized hit job was being undertaken against Lifelock.

So far as the organized hit job theory, it does have some merit. The reason for this is that Lifelock's service isn't much different than what a lot of other companies are offering. Additionally, the repetitive fraud alerts make it more expensive to issue credit, and there is a cost incurred by the credit bureaus for providing them.

Then there is the competitive edge, identity theft protection services are being hawked by a lot of different companies. They range from unknown start-ups to financial institutions and the credit bureaus, themselves. In not very good economic times, the industry is showing double-digit growth.

The Motley Fool gave a good explanation of the reason for this in their article (one of the recent 339 or so) about Lifelock:

There's clearly profit to be had in the privacy protection market -- much-needed profit for credit reporting-related services. The 2003 passage of the Fair and Accurate Credit Transactions Act (FACT Act) handicapped one of their revenue streams by mandating free credit reports for all. (Get yours at annualcreditreport.com.)

To help make up for the financial shortfall, the credit reporting companies created a new revenue stream: credit watch products. Seeing profit in consumer fear, other companies soon created their own credit watch muscle for hire.

Please note, the article in the Motley Fool gives some pretty sound advice about how to protect yourself for free from identity theft, also.

Then came the legal actions, first Experian filed a law suit and then came a series of class actions alleging the Lifelock is guilty of misleading advertising, doesn't warn it's customers that it only provides limited protection and doesn't warn them that repetitive fraud alerts might damage their credit rating.

I suspect the current flurry of stories were partially the result of information released from the law offices in the class action suits that Todd Davis has been the victim of identity theft numerous times.

It's now been revealed that Davis' identity has been compromised 87 times in the past two years. 20 of these attempts involved drivers licenses. Davis has responded by stating that this proves Lifelock protects it's consumers from identity theft since the only known successful attempt was with the PayDay loan in Texas.

While this might be partially true, there is a flaw in this thinking. The flaw is that partial information isn't always picked up by credit bureaus and credit bureaus don't detect all forms of identity theft.

A new buzz word in identity theft circles is "synthetic identity theft." Here is a description of it from a previous post:

This is where different parts of other people's identities are used to forge a synthetic one. Quite often, because a lot of the information doesn't match, the credit bureaus don't pick it up. Most frequently, this is discovered at tax time, when someone gets a bill for taxes that an identity thief never paid to the government.

So far as identity theft that isn't picked up on a credit bureau, here is what I wrote about that in the same post:

Another reason there is no way to guarantee protection is that not all identity theft shows up on credit bureaus. Some examples of this are in cases of medical benefit fraud, employment fraud, government benefit fraud, some forms of check fraud and last, but not least, when it is used to commit crimes of other than a financial nature.

Because of these reasons, I'm not certain if Mr. Davis can be sure that all 87 attempts were entirely unsuccessful?

Another marketing claim that many feel is misleading is Lifelock's $1 million dollar guarantee. If you read the fine print, they only guarantee they will hire people to look into it should you become a statistic while using their service. They also stipulate that they will choose who does this for you.

Trust me, it's highly unlikely anyone will collect much of anything if they become an identity theft statistic while paying for Lifelock. In most instances, after the work is done, the financial institutions end up responsible for the loss.

Of course, when this happens the cost is passed on to all of us. No business would be able to remain solvent, otherwise.

The sad truth is that there really is no guarantee that you will never become an identity theft victim and it's probably better to exercise common sense and perform your own due diligence.

Since I seem to be quoting myself a lot in this post, here is something I wrote about this:

Most of the experts (not selling services) agree most people can fix their identity for free, and in the long run, they might do a better job of it, themselves.

If someone were to do this, a good place would be the FTC's Identity Theft page. Other decent free resources are the Identity Theft Resource Center and the Privacy Rights Clearinghouse.

Last, but not least, the good folks at Attrition.org did a highly amusing parody of identity theft protection services after they got sick and tired of them using their free material:

Going forward, we would like to announce that we have a new partnership with Identity-Love-Sock, a trusted provider of identity theft prevention services. Not only can Identity-Love-Sock protect YOU from IDENTITY THEFT, it also provides several guarantees for your PROTECTION should YOU be affected by IDENTITY THEFT. With the services provided by Identity-Love-Sock , YOU will NEVER have to WORRY about your IDENTITY being STOLEN, MISUSED, or otherwise COMPROMISED. For more details on how YOU can be COVERED and PROTECTED, please visit Identity-Love-Sock . You'll be glad you did.

Along with covering various matters related to computer security and privacy, Attrition is recognized for maintaining a pretty telling database on where a lot of identity theft starts, or data breaches.

Saturday, May 03, 2008

Does the proposed class action settlement in the Certegy data breach case lack teeth?

I happened to notice, I was getting a lot of hits on some posts about the Certegy data breach and discovered that there is a proposed settlement in the class action law suit against them.

Tim Wilson at Dark Reading pointed out that this settlement amounts to Certegy paying less than $1 per victim and wrote:

Certegy Check Services is proposing to settle a class action lawsuit of last year's security breach on behalf of 8.4 million victims for about $4 million.

According to a report in the St. Petersburg (Fla.) Times, Certegy will also offer free credit monitoring services to some victims and reimbursement of credit monitoring expenses totaling $1 million on a first-come-first-served basis.
He also surmised in his article that:

While plaintiffs' lawyers hailed the offer as a victory, critics said the relatively small settlement will not help the cause of identity protection. The massive TJX breach also resulted in a relatively small settlement for the victims, netting about $6.5 million for customers.

Of note, I would imagine the plantiff's lawyers made A LOT more than $1 each for orchestrating this event. In all fairness, given the precedent set by similar actions might mean there isn't a very "deep pocket" on this type of action.

At $1 million for monitoring divided by 8.4 million potential victims, if any of them want the free monitoring, they better move quickly.

So far as the $4 million being set aside to make victims whole, I wonder how hard it is going to be for them to prove (as required by this settlement) that Certegy was the point-of-compromise in their case? The general rule of thumb is that identity thieves, even if they are caught (rare), probably aren't 100 percent sure where the information came from themselves. There is so much stolen information out there, it's being traded over the Internet.

The sad truth is that with all the data breaches out there, it might be hard to prove exactly where an identity theft victim's information was compromised.

So far as the criminal prosecution of the employee, one William Sullivan, who sold off 8.5 million people's records, I did a post in November about how he was able to make a plea bargain and get a reduced sentence in this case. There was a mention of a data broker being a co-conspirator, but they never seemed to be named (at least in public).

Personally, I've always had mixed feelings about law suits that result when data breaches occur. There is an argument that at least some (my opinion) of the organizations being breached are victims in the overall equation, also.

Saying that, if this class action and the one for TJX have set the legal precedent on this type of action, they are unlikely to serve as much of a deterrent against data breaches, or all the identity theft that results from them. Furthermore, the criminal prosecution of William Sullivan in his case is unlikely to be much of a deterrent, either.

In fact these results are probably going to do little to inspire organizations to protect their information better and for some, will probably be viewed as a cost of doing business.

I guess it's time to go back to the drawing board to figure out a way to effectively address information/identity theft and data breaches?

Here are the original posts, I did on this matter, which contain some angry commentary from more than one victim:

Not to worry, check processing company (Certegy) believes the 2.3 million stolen records will not be used for fraud!

Certegy reveals their data breach is a lot larger than originally reported

Class action law suit filed against Certegy for data breach

Saturday, March 29, 2008

Lifelock is getting sued, again!

Lifelock -- the identity theft service founded on an identity theft tale that was later deemed not to be very credible -- is now facing another law suit. This one, which is of the class action variety, alleges that their advertising is misleading and they don't necessarily protect a person from all the different varieties of identity theft.

From the press release on the Hagens Berman LLC site:

Today an Arizona consumer filed a proposed class-action lawsuit against LifeLock, a heavily promoted company that claims to protect consumers against identity theft. The lawsuit alleges that the three-year-old company defrauds customers by offering services it cannot legally perform, and by touting a $1 million guarantee that the suit alleges is wildly misleading.
The suit also alleges that Lifelock doesn't protect a person from all the forms of identity theft citing a case where -- Lifelock's flamboyant CEO (Todd Davis) who plasters his social security number everywhere as a marketing tool -- had his own identity stolen.

The press release didn't mention that the case was dropped after Davis employed a PI, along with a film crew to obtain a confession from the identity thief. Reportedly, the reason the case was dropped is because of a legal term called, "coercion."

One point of contention in the law suit is that the $1 million guarantee Lifelock promises is deceptive and laden with fine print:

Its advertisements prominently feature a supposed $1 million guarantee. In one commercial, Todd Davis, a founder and CEO of LifeLock, announces to a crowd of individuals, "If anything happens for any reason while you're a client of LifeLock, we will cover all losses and all expenses up to one million dollars." On its Web site, LifeLock makes similar statements, claiming that it will "do whatever it takes" to restore a member's good name.

According to the complaint, the fine print says otherwise: LifeLock will not pay any losses directly to the consumer and does not cover consequential or incidental damages to identity theft. The guarantee is limited to fixing failures or defects in the LifeLock services and paying other professionals to attempt to restore losses.

In this first paragraph of this post, I mentioned that Lifelock is getting sued again. Recently, one of the big three credit bureaus (Experian) filed a law suit for the costs of placing and replacing alerts on people's credit files.

In this post, I covered that the fact the credit bureaus are also in the identity theft protection business and that other companies (Debix, TrustedID) offer essentially the same service that Lifelock does.

This brings about speculation that both of these actions against Lifelock have the potential to set legal precedents and might bring about additional actions in the future. There has also been speculation that there is a "turf war" going on between Lifelock and the big three credit bureaus.

There is no guarantee what will become of all of this. The sad fact is that identity theft is a growing problem. Because of this, there are a lot of people getting involved in the identity theft protection business. The last time I checked, the industry was showing double-digit growth. This alone is quite remarkable considering the current state of the economy.

Given the fact that this is an "unregulated" industry involved in assisting victims of crime, everyone involved in it needs to take a hard look at the product they are offering to ensure it passes the "smell" test.

If they fail to do so, they will probably subject themselves to bad press, litigation and potentially government intervention (regulation).

They need to remember that identity theft victims are people, who fell victim to a crime that happened because their information was stored in too many places and WAS NOT protected properly. Of course, saying that, the people buying and selling information make a lot of money from doing it, also.

The sad truth is everyone is making money from this except the identity theft victim.

The post, I did on the first Lifelock law suit contains links to free resources to protect yourself and recover from identity theft. It also highlights a few of the organizations that are actively trying to do something about the overall problem identity theft has become without making a profit off it.

That post can be seen, here.

Friday, August 17, 2007

Class action law suit filed against Certegy for data breach

Data breaches are likely to become costly to organizations who fail to protect their information. The TJX data breach (45 million people and counting compromised) has inspired several legal actions in both the United States and Canada.

Now a similar action is being brought against Certegy, a check verification company, who had an insider sell information to a still (as far as I know) undisclosed data broker.

An August 15th press release announced:

The law firm of Girard Gibbs LLP (http://www.girardgibbs.com/) has filed a class action complaint on behalf of approximately 8.5 million consumers nationwide whose financial and personal data was stolen by an employee of Certegy Check Services, Inc. and Fidelity National Information Services, Inc (NYSE: FIS) and released to unauthorized third parties. The complaint alleges that a senior database administrator misappropriated the confidential information of millions of consumers and then sold the data to direct marketing firms and data brokers who may have resold it to others.

Certegy and FIS had a duty to safeguard the confidential data of consumers from any breach, including that of their employees. Once the internal breach became known, it should have been communicated to the public in a timely and adequate manner,” said Eric Gibbs, one of the attorneys for the plaintiff. “The failure by these companies to make the internal data breach immediately known exposed consumers to direct marketing campaigns and the risk of unauthorized use of their bank accounts and identity theft.”
This case is interesting because it involves customer information that was obtained at merchants, who used the service to verify whether a person's check, or sometimes payment card was good.

I wrote a couple of posts about Certegy, which received a lot of comments. One comment (in my opinion) by a "Risk Manager" opened up another can of worms:

I think there is a bigger issue here that Certegy does not "own" the data that was stolen but in fact it is records of Certegy customers like businesses that contract Certegy for check-cashing services. I would ask Certegy to confirm what they store on their systems, how long they store it and why bank account and credit card numbers are stored AND investigate if Certegy violated any Visa/PCI mandates.

This seems to be a reasonable question, especially in light of some of the more high profile data breaches, we've recently seen. However in this instance, since all it takes is one person (who has access) to compromise information, it probably wouldn't have made much difference.

The reality is that Certegy sells the fact that they store a lot of information on people to merchants. Without this information, they wouldn't have a service to sell.

Nonetheless, the statement does warrant consideration as to how well third party databases are protected, especially when they contain detailed personal and financial information?

I'm not sure why the data broker, who bought the information hasn't been identified? They are responsible for buying and selling information all the time. Information is worth money and is being sold (some believe haphazardly) all the time.

Recently, it was disclosed that a data broker sold lists targeting elderly gamblers to sweepstakes (lottery) scammers. New York Times article, here.

Current laws enable financial institutions to sell your information, unless you go through a pretty complicated process of opting-out. They are required by law to notify you of your rights, but these are often sent out via snail mail and called "privacy notices." I've often made the mistake of thinking they were junk mail and shredded them.

They don't make it easy for the average person to protect their information.

I wonder how much personal information is sold to people that shouldn't be getting it? Even if we manage to opt-out today, how much of our information is already stored on a database somewhere?

Since the people enabling information to be compromised are making billions of dollars by selling it -- perhaps more of these lawsuits are one way to hold them accountable and bring some sanity to what is becoming a situation -- which seems to get worse all the time?

Of course, more laws to protect consumers are needed, also!

As I stated earlier, this is going to be interesting. I don't know where it will go, but maybe this is a signal to the people data mining our information to wake up and smell the coffee?

If they don't, they might end up dealing with a lot of litigation, which is always very costly.

It also might put them out of business. Dark Reading did an article this week about another third party vendor Verus, who folded after it was disclosed that they lost a lot of people's information from several hospitals. The point of compromise in this situation was the failure of some IT people to leave a firewall up when transferring information between servers.

Here are my two previous posts on the Certegy breach:

Not to worry, check processing company (Certegy) believes the 2.3 million stolen records will not be used for fraud!

Certegy reveals their data breach is a lot larger than originally reported