Feeds

Fraud-prevention service ponies up $12m for 'false' ads

Agrees to safeguard customer data

The Essential Guide to IT Transformation

An Arizona company that sells services designed to prevent identity theft has agreed to pay $12m to settle charges it oversold their effectiveness and didn't adequately protect sensitive customer data.

LifeLock, which since 2006 has run TV and print ads displaying the social security number of its CEO, agreed to stop misrepresenting its service as a foolproof way to prevent identity theft, according to the US Federal Trade Commission. The consumer watchdog agency and attorneys general from 35 states claimed the company's $10-per-month service failed to stop the most prevalent forms of the crimes.

A complaint filed in federal court in Arizona alleged that alerts LifeLock placed on customer credit files protected against only so-called new account fraud, in which scammers open new credit accounts using the name and social security number of the victim. New account fraud accounted for just 17 per cent of identity theft incidents, according to an FTC survey released in 2007.

LifeLock was unable to prevent medical identity theft and employment identity theft, in which crooks use personal information to get medical care or apply for jobs, the FTC said. It was also ineffective at protecting against abuse of existing accounts.

The agreement also took aim at claims LifeLock made that it routinely encrypted customers' social security and credit card numbers and granted its employees access to such data strictly on a need-to-know basis. FTC attorneys charged that such claims were false. The settlement requires LifeLock to establish a comprehensive data security program and obtain independent third-party assessments for 20 years.

LifeLock has come under criticism for ads that claimed it could protect customers against identity theft. Although CEO Todd Davis said he was so confident in the service he was willing to publicly post his social security number, he has regularly been the victim of such crimes. Competitor Experian has also sued LifeLock for fraud.

Of the settlement amount, $11m will be paid to the FTC and the remaining $1m will go to the 35 states that were part of the action. The FTC has more here. ®

Build a business case: developing custom apps

More from The Register

next story
14 antivirus apps found to have security problems
Vendors just don't care, says researcher, after finding basic boo-boos in security software
'Things' on the Internet-of-things have 25 vulnerabilities apiece
Leaking sprinklers, overheated thermostats and picked locks all online
Only '3% of web servers in top corps' fully fixed after Heartbleed snafu
Just slapping a patched OpenSSL on a machine ain't going to cut it, we're told
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Secure microkernel that uses maths to be 'bug free' goes open source
Hacker-repelling, drone-protecting code will soon be yours to tweak as you see fit
Israel's Iron Dome missile tech stolen by Chinese hackers
Corporate raiders Comment Crew fingered for attacks
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Backing up Big Data
Solving backup challenges and “protect everything from everywhere,” as we move into the era of big data management and the adoption of BYOD.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.