Feeds

Fraud-prevention service ponies up $12m for 'false' ads

Agrees to safeguard customer data

Internet Security Threat Report 2014

An Arizona company that sells services designed to prevent identity theft has agreed to pay $12m to settle charges it oversold their effectiveness and didn't adequately protect sensitive customer data.

LifeLock, which since 2006 has run TV and print ads displaying the social security number of its CEO, agreed to stop misrepresenting its service as a foolproof way to prevent identity theft, according to the US Federal Trade Commission. The consumer watchdog agency and attorneys general from 35 states claimed the company's $10-per-month service failed to stop the most prevalent forms of the crimes.

A complaint filed in federal court in Arizona alleged that alerts LifeLock placed on customer credit files protected against only so-called new account fraud, in which scammers open new credit accounts using the name and social security number of the victim. New account fraud accounted for just 17 per cent of identity theft incidents, according to an FTC survey released in 2007.

LifeLock was unable to prevent medical identity theft and employment identity theft, in which crooks use personal information to get medical care or apply for jobs, the FTC said. It was also ineffective at protecting against abuse of existing accounts.

The agreement also took aim at claims LifeLock made that it routinely encrypted customers' social security and credit card numbers and granted its employees access to such data strictly on a need-to-know basis. FTC attorneys charged that such claims were false. The settlement requires LifeLock to establish a comprehensive data security program and obtain independent third-party assessments for 20 years.

LifeLock has come under criticism for ads that claimed it could protect customers against identity theft. Although CEO Todd Davis said he was so confident in the service he was willing to publicly post his social security number, he has regularly been the victim of such crimes. Competitor Experian has also sued LifeLock for fraud.

Of the settlement amount, $11m will be paid to the FTC and the remaining $1m will go to the 35 states that were part of the action. The FTC has more here. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Why did it take antivirus giants YEARS to drill into super-scary Regin? Symantec responds...
FYI this isn't just going to target Windows, Linux and OS X fans
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
Home Office: Fancy flogging us some SECRET SPY GEAR?
If you do, tell NOBODY what it's for or how it works
Syrian Electronic Army in news site 'hack' POP-UP MAYHEM
Gigya redirect exploit blamed for pop-rageous ploy
prev story

Whitepapers

Go beyond APM with real-time IT operations analytics
How IT operations teams can harness the wealth of wire data already flowing through their environment for real-time operational intelligence.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Why CIOs should rethink endpoint data protection in the age of mobility
Assessing trends in data protection, specifically with respect to mobile devices, BYOD, and remote employees.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Seattle children’s accelerates Citrix login times by 500% with cross-tier insight
Seattle Children’s is a leading research hospital with a large and growing Citrix XenDesktop deployment. See how they used ExtraHop to accelerate launch times.