Custom Search
Showing posts with label data breach. Show all posts
Showing posts with label data breach. Show all posts

September 08, 2017

Too Little, Too Late - Equifax Adds Opt Out to Arbitration Provision regarding Data Breach

After a flurry of bad press and social media outrage (including from yours truly), Equifax has now added an opt out provision to the arbitration provision it snuck into the fine print for anyone accepting Equifax's "offer" of "free" credit monitoring and identity theft protection.

Couple of problems.  No one reads the fine print so they don't know about the arbitration clause, much less the opt out provision.  Why can't they just make it an opt in, if arbitration is such a great thing?  Of course, its not and they won't.

Second, the opt out provision is only available for a measly thirty days from when the data breach victim signs up for the "free" credit monitoring.  Equifax kept the data breach secret for longer than that!  Thirty days is way too short.

And, a common ploy on these opt out provisions for arbitration clauses is that, amazingly, the company whose arbitration clause it is almost always denies that the consumer ever opted out and then still try to force the consumer into proving that he or she opted out, instead of the burden being on the company to prove that the consumer agreed to arbitration. Equifax will likely try the same ploy since, as you can see, the play fast and loose with the rules.  Just do a pacer search for lawsuits where they have allegedly violated the Fair Credit Reporting Act.

The data breach is a very bad thing.  But Equifax's reaction to the data breach (i.e. keeping it secret for almost two months and then trying to screw the data breach victims out of their rights) is the worst of all.  Equifax and its executives should pay and pay dearly for this.


Congressional Committee to hold Hearing Regarding Equifax Data Breach

Yesterday, the House Financial Services Committee held a hearing on a bill that would gut the protections of the Fair Credit Reporting Act, which is the only law protecting Americans from the ridiculously inept consumer reporting agencies such as Equifax.

Today, the public learned of a massive data breach of Equifax's treasure trove of secret information regarding consumers, including the full names, Social Security numbers, dates of birth and addresses of approximately 143 Americans.

Now, the House Financial Services Committee released the following press release:

"WASHINGTON – House Financial Services Committee Chairman Jeb Hensarling (R-TX) said his committee will hold a hearing on the Equifax data breach that has potentially compromised the personal information of roughly 143 million Americans.

“This is obviously a very serious and very troubling situation and our committee has already begun preparations for a hearing.  Large-scale security breaches are becoming all too common.  Every breach leaves consumers exposed and vulnerable to identity theft, fraud and a host of other crimes, and they deserve answers,” said Chairman Hensarling.

A date for the hearing will be announced at a later time."

Chairman Hensarling, if you want to protect Americans from data breaches and the damage caused by identity theft, your first step should be to kill HR 2359.  Only the Fair Credit Reporting Act stands in the way of Equifax and the other credit bureaus harming Americans by willfully and knowingly reporting erroneous information on Americans' credit reports.  That is the "answer" you seek.  Have you hearing, but start with killing HR 2359 and let the Fair Credit Reporting Act continue to protect Americans.

Equifax's data breach just keeps getting worse!

As if it is not bad enough that Equifax exposed 143 million Americans to the hellacious ordeal of identity theft, now its becoming crystal clear just how inept their response to the data breach was.

For instance, the website ARS Technica (www.arstechnica.com) reported the following:

"What's more, the website www.equifaxsecurity2017.com/, which Equifax created to notify people of the breach, is highly problematic for a variety of reasons. It runs on a stock installation WordPress, a content management system that doesn't provide the enterprise-grade security required for a site that asks people to provide their last name and all but three digits of their Social Security number. The TLS certificate doesn't perform proper revocation checks. Worse still, the domain name isn't registered to Equifax, and its format looks like precisely the kind of thing a criminal operation might use to steal people's details. It's no surprise that Cisco-owned Open DNS was blocking access to the site and warning it was a suspected phishing threat.

Another indications of sloppiness: a username for administering the site has been left in a page that was hosted here. ... That by itself wouldn't allow for unauthorized access, but it's still something that should never have happened.

Meanwhile, in the hours immediately following the breach disclosure, the main Equifax website was displaying debug codes, which for security reasons, is something that should never happen on any production server, especially one that is a server or two away from so much sensitive data. A mistake this serious does little to instill confidence company engineers have hardened the site against future devastating attacks."

So Equifax's attempt to "fix" the damage done by its data breach doesn't just take away the rights of consumers to get justice for the damage caused by Equifax's negligence, it now opens those victims up to more potential privacy problems by using a website with obvious security holes to collect the names and Social Security numbers of the victims.  Sheeeeesh!

Equifax's unwillingness to investigate consumer disputes properly is starting to look like the lesser of their sins.

Equifax Data Breach Puts 143 Million Consumers at Risk

On July 29 (yes, nearly two months ago), Equifax discovered that it had suffered a data breach between mid-May and July.  The massive data breach exposed the personal identifiers of approximately 143 million Americans.  That means approximately half of the population of the United States just became even more likely to have their identities stolen.

The information that Equifax allowed to be stolen is the holy grail for identity thieves.  The names, Social Security numbers, dates of birth, addresses and, in some cases, driver's license numbers of 143 million Americans were pilfered from Equifax.  Even worse, Equifax sat on this information for nearly two months before alerting the public of Equifax's malfeasance putting them at risk.

Equifax is one of the last companies that should allow something like this to happen.  Equifax chose to enter the business of collected and disseminating the most private of information on nearly all Americans.  Equifax's credit reports are used nationwide for obtaining home loans, car loans, credit cards, bank loans and lines of credit.

Equifax's credit reports are used by many employers to decide whether to hire someone, particularly if there is any responsibility for financial accounts involved in the job description.

Equifax's credit reports are used by government agencies to determine whether you can have or keep a security clearance.  I have had many clients lose their security clearances (and thus their jobs) due to Equifax reporting erroneous information about them and the willfully refusing to correct the errors.

Equifax's credit reports are used by insurance companies to determine if you qualify for car insurance and homeowner's insurance.  And, if you do qualify, you may find that your premiums are higher because of the contents of your Equifax credit report.

Now, all of that uber sensitive information entrusted to Equifax (not that the consumer is given an option) has been exposed to identity thieves and hackers and is no doubt going to be sold on the dark web and used to victimize consumers across the country.

But what is even worse than Equifax allowing this tragedy to happen and then keeping its misdeeds secret for nearly two months?  Now, Equifax is offering free identity theft protection and credit monitoring to the victims of its data breach.  Sounds good, right?  Wrong!  Included in the sign up for that "free" identity theft protection are arbitration clauses that take away your rights to sue Equifax for the damage its data breach causes you.

When my wife woke me up this morning at 2:00 a.m. when she read about the Equifax data breach and then told me that Equifax was offering free credit monitoring and identity theft protection, I mumbled in my half awake state "do not sign up for it, they'll  have something bad in the fine print". How did I know this?  Well, for one, I have been suing Equifax for consumers they have wronged for nearly 18 years now.  Second, Equifax has done this type stuff before.  For instance, consumers are entitled under the Fair Credit Reporting Act to one free credit report per year.  But Equifax thought it right to make consumers agree to give up their right to a lawsuit to be able to exercise their right to a free credit report.  So Equifax stuck some arbitration language in the fine print of anyone accessing their free credit report online.  I warned you about this all the way back in 2009 - fcralawyer.blogspot.com/2009/05/truly-free-credit-report.html.  So it was no surprise that they would pull something like this again, especially since they are the root cause of the problem this time.

So, if Equifax's data breach causes your identity to be stolen which then causes your life to become a financial hell when your legitimate credit cards get closed, you lose your job and your home and auto insurance and then, due to the stress of it all, your health goes kaput, Equifax skates by free and clear because your only option is to bring an arbitration proceeding to be decided by Equifax's arbiter. Talking about heaping injustice on top of tragedy!

So, whatever you do, do not sign up for Equifax's "free" monitoring or identity theft protection.  To do so will cause irreparable harm to any potential lawsuit you may have if, God forbid, Equifax's data breach leads to theft of your identity.  And, if you do become the victim of identity theft, contact the Kittell Law Firm at 662-298-3456 or at ckittell@kittell-law.com.  I will sue Equifax in any jurisdiction in the United States for any victim of identity theft whose credit report is damaged as a result of Equifax's data breach provided that you have not agreed to throw your rights away by falling for Equifax's trap of "free" credit monitoring.


January 24, 2013

Huge Data Breach At South Carolina Department of Revenue


As I learned today, the powers that be at the South Carolina Department of Revenue did not believe they needed all the security features to protect the information included with the tax returns sent when tax payers electronically filed  their returns.  As a result, the information of 3 million people and over 200,000 businesses was stolen by a data thief in Eastern Europe.

What's even worse than being exposed to identity theft by an Eastern European identity theft ring?  Having the state that did not care enough to protect your data "compensate" you for the risk it put you in by signing you up for a year's worth of credit monitoring from Experian.  Why is that so bad (other than the fact that credit monitoring does not help protect consumers much, if any)?  Because Experian requires anyone using their monitoring service to agree to binding arbitration.  So for the 3 million South Carolinians and 200,000 plus South Carolina businesses to receive the offered "protection" from the risk of identity theft caused by South Carolina's negligence, the consumers and businesses have to give up their right to a jury trial against Experian, which basically means they lose again if their identity is actually stolen.  

South Carolina, you should be ashamed of yourself for doing this to your own people.  My advice to those affected in South Carolina.  Don't use the monitoring service.  Instead, use annualcreditreport.com and stagger  your annual three free credit reports (one from each of the big three credit bureaus) to one every four months and thereby monitor your credit for free without giving up any of your rights.  Oh, and if your identity is stolen, hire the Kittell Law Firm to sue the credit bureaus and creditors who refuse to remove the fraud accounts that will show up on your credit reports.  

June 18, 2012

Potential data breach at the University of North Florida

From the Florida Times-Union's Jacksonville.com website:

A computer database containing information about 23,246 people who submitted contracts to live in the University of North Florida’s residence halls might have been compromised by a hacker.

School officials have locked down the affected computer server as they try to find out if any personal information was taken.

The database included names and Social Security numbers of people who submitted housing contracts between 1997 and spring 2011. The hacking could have occurred as long as a year ago, according to UNF officials.

“When we first started to suspect someone who was not authorized had gotten into the database, we immediately began investigating,” UNF spokeswoman Sharon Ashton said. “At the same time, we moved the information off that server and put it on a different server, and put additional security measures in place.”

The investigation needed a few weeks to determine which file was broken into, then how to get in touch with everyone on it to alert them to the breach, Ashton said. Now the university is sending them letters and emails about the breach.

“We don’t have any evidence that any information, or that anything, was copied from the files, but it is a possibility,” Ashton said.

So far, Ashton says, none of the people that were in the database have reported their personal information was used. The school will pay for one-year memberships in a credit-protection program for anyone impacted. It has set aside $80,000, but is prepared to pay for all 23,246 if they request it. And school officials recommend they place a fraud alert on their credit files via Equifax, (800) 525-6285; Experian, (888) 397-3742; or Trans-Union, (800) 680-7289.

In October 2010, someone gained access to personal information on almost 107,000 UNF students, potential students and employees. Other universities have been affected by hackers more recently.


The University of Nebraska identified an undergraduate student in May it says is responsible for breaking into a school database with information on more than 650,000 students, parents and employees, according to www.computerworld.com. And in January, Arizona State University shut down its web services after someone downloaded an encrypted file containing user names and passwords of an unknown number of students, faculty and staff, according to the school.

April 02, 2012

Yet another data breach putting millions of consumers at risk

Global Payments is a company that processes credit card transactions.  It announced late Friday (conveniently near the close of business right before the weekend) that a data breach may have allowed unauthorized access to 1.5 million credit card numbers.  Global Payments would not say what types of credit cards were potentiall affected, but Visa confirmed that the data breach included all of the major players (i.e. Visa, Mastercard, Discover, etc.).

Global Payments also released a statement on Sunday with more details.  Most importantly, according to Global Payments' statement, the data breach did not include cardholders' names, addresses or Social Security numbers.   That should lessen considerably the risk of true name identity theft, but the risk of account take over via the compromised credit card numbers is still present.

SO what should the consumer do?  Same as always - watch your credit card statements for any transactions that you did not make.  If you find one, report it as fraud.  The credit card company should eat the charge and issue you a new card with a new card number.  Considering 1.5 million is only a very small percentage of the estimated one billion credit and debit card numbers being used in the U.S., the chances that this data breach will affect you is slim.

October 04, 2011

Horrible - TriCare refuses to provide credit monitoring to the victims of its data breach

TriCare is a healthcare program that provides healthcare coverage to uniformed service members, retirees and their families.  Last month, a number of TriCare's computer backup tapes were stolen from the vehicle of an employee of Science Applications International Corp.  The tapes contained the personal information (including Social Security numbers) and health information of 4.9 million beneficiaries.

Typically, companies that allow such massive data breaches to occur will offer free credit monitoring services to the victims of its negligence.  But not TriCare.  Its refusing to do the right thing.

According to TriCare, it was not offering credit monitoring services because "retrieving the data on the tapes would require knowledge of and access to specific hardware and software and knowledge of the system and data structure."  Hog wash.  Does TriCare not realize what the technologically savvy can do with computers these days?  It wouldn't take a moderately skilled hacker any time at all to successfully access the information on those tapes.

TriCare, get your head out of the sand and offer the credit monitoring service to your victims.  Its not much, but its at least something.

September 29, 2011

Thousands at risk of identity theft from stolen laptop

A stolen laptop has put thousands of former patients of two Minnesota medical care providers at risk of identity theft.  A laptop containing the personal identifiers and other private information of approximately 14,000 patients of Fairview Health Services and 2,800 patients at North Memorial Medical Center, both of Minneapolis, was stolen out of a locked car located in the parking lot of a Minneapolis restaurant.

What's worse?  The data on the computer was not even encrypted.  In this electronic age, there's simply no excuse for massive amounts of personal identifiers not to be encrypted.

What's worse than that?  The medical care providers knew of the stolen laptop mere days after it was stolen on July 25 but are just now taking steps to inform the patients of the privacy breach.  Two months worth of proactive measures are now lost to these victims.

"Obviously, we take this event seriously," said Dr. Mark Werner, one of the senior physician leaders at Fairview. "It's deeply regrettable."

Obviously not.  Or you would have informed these patients whose identities your company exposed much, much sooner.  Just this week, two months too late, letters are being sent to those potentially affected, informing them of what happened and offering free services to protect them from identity theft.

The medical care providers claim "there's no evidence that the information has been misused."  Well, of course there's no evidence of any misuse.  You've kept the only people (other than the identity thieves) that would know of the misuse in the dark for the past two months.  Its very likely the identity thieves have already run amok using the credit histories of their victims and, if the victims are even aware of the theft of their identities, they have not linked the crime to the gross negligence of their medical care providers in failing to properly secure their personal identifiers. 

Give it a few more months (assuming those letters really do go out this week) and I bet there will be truckloads of "evidence of misuse". 

To those unfortunate victims of Fairview Health Services and North Memorial Medical Center, you need to check your credit reports, aggressively dispute any errors (whether resulting from identity theft or not) and then hire an attorney versed in the intricacies of the Fair Credit Reporting Act to represent you against the medical care providers who breached your trust and against any credit bureau or furnisher who refuses to correct your credit histories.  If you need the name of a good FCRA attorney in Minnesota, contact me and I will be happy to provide one.

February 16, 2010

Potential Blue Cross ID Theft Victims Top 500,000

Look out, former and current members of Blue Cross and Blue Shield of Tennessee.  Another 301,628 of you are going to find out shortly that you may be another victim of identity theft.  Don't worry, you've got company, as 220,133 people were already notified of their potential fate.

Last year, computer hard drives were stolen that happened to contain the personal identifiers and other information regarding over 500,000 members of Blue Cross/Blue Shield of Tennessee.

Blue Cross is offering free credit and ID remediation to those potentially affected.  Whoop tee do.  That's like offering a condom to a pregnant woman.  Nice gesture, but a little bit ineffective at this point.

Blue Cross should be offering these people cold hard cash for the worry and stress of potentially being a victim of identity theft.  These people paid good money to Blue Cross to insure them.  Blue Cross, they trusted you to keep their personal identifiers and medical information secure.  But you didn't.  Now over 500,000 people are at risk of one of the worst things that can happen to anyone, losing their good name due to the fault of another. 

I bet if the big wigs at Blue Cross had their identity stolen, they would be the first to balk at "free credit and ID remediation" and demand real justice.  Now lets see if they will step up for their customers.

February 09, 2010

Alaska employees at risk of identity theft - push Equifax to establish call center

From newsminer.com - 77,000 current and retired public employees from 2003-2004 at risk of identity theft due to security breach by PriceWaterhouseCoopers.  Read on.
The 77,000 current and retired public employees who may be at risk for identity theft because of information lost by a state contractor should receive letters within the next week or so with details on what to do next. The state is pressing a major credit agency to get a call center in place, perhaps by Feb. 15, to process individual cases.

There have been no reports yet of cases of identity theft resulting from the loss of the prices information, but unless or until PriceWaterhouseCoopers recovers the lost information, the risk remains.

The names, Social Security numbers and birth dates of employees or former employees who were in the Public Employees Retirement System and the Teachers Retirement System in 2003-04 were lost by PricewaterhouseCoopers in Chicago in early December.
The company, which failed to tell the state about its mistake for nearly two months, said in late January that it “regrets that the information was misplaced” and that it has made a “significant commitment” in trying to protect the people at risk.

The information was given to the accounting firm for analysis of financial models which are part of building the state’s lawsuit against Mercer, the company that the state claims mishandled the investments in the two retirement systems, creating losses in the billions.

Part of the settlement is that PricewaterhouseCoopers is to provide credit protection and safeguards for the 77,000 people, who are state and local government workers, teachers, university employees and retirees.

Department of Administration Commissioner Annette Kreitzer said the credit rating agency Equifax is being pressed to get the call center in place as soon as possible that will allow individuals to check on their records and take precautionary measures.

Equifax says it won’t be ready with its call center until Feb. 15, she said.
Kreitzer said a letter with instructions on how to contact the center and a unique code for each person is to be sent out late next week.

“I have questioned whether the call center could be set up more expeditiously, but Equifax has maintained that it cannot,” she said.

“The worst thing we could do is give the instructions out and then have people more frustrated because Equifax hasn’t had time to train its call center operators with our specific settlement information,” she said.

January 13, 2010

Data breach thwarted by Suffolk Bancorp

Suffolk Bancorp (NASDAQ - SUBK) announced today that on December 24, 2009, its banking subsidiary, the Suffolk County National Bank ("SCNB") discovered through an internal security review that an unauthorized intruder accessed certain customers' Log In information via the computer server hosting SCNB's Online Banking system.

Based on SCNB's investigation, which is ongoing, the unauthorized access occurred during a finite, six-day-period between November 18 and November 23, 2009. 8,378 Online Banking customers were affected, amounting to less than 10 percent of SCNB's total customers. Although the intrusion was limited in duration and scope, SCNB immediately isolated and rebuilt the compromised server and took other measures to ensure the security of data on the server. To date, SCNB has found no evidence of any unauthorized access to Online Banking accounts, nor received any reports of unusual activity or reports of financial loss to its customers.
SCNB has taken a number of additional steps to minimize any possible effect of this incident on its customers.

December 28, 2009

Countrywide settles class action lawsuit for mere "slap on the wrist"

What a crock.  Countrywide, who allowed a rogue employee to steal the personal information of over 17 million of its customers (me included), has achieved preliminary court approval for its settlement of a class action lawsuit filed against it.  The proposed settlement - Countrywide (now owned by Bank of America) - gives each of the potential victims a wopping settlement of ... drum roll please ... free credit monitoring!  Whoo whoo, go cash that voucher in quick, its worth sooooo much more than your good name!  Can you smell the sarcasm?!

What a joke of a settlement.  I for one will be opting out.  Don't know if I will sue separately yet or not, may even be past the statute of limitations, but I am definitely not going to accept free credit monitoring in settlement of anything.

Oh, the settlement does provide for up to $50,000 for anyone that can prove their identity was stolen as a result of Countrywide's data breach but, surprise surprise, no one's been able to meet Bank of America's burden of proof on that one yet.  Not that $50,000 is much for an identity theft victim.  I fairly routinely get multiples of that for my clients. 

Shirley Norton, a spokeswoman for Bank of America, said the settlement is “in the bank's best interest” to avoid additional legal expenses. "We look forward to moving ahead with the settlement,” Norton said.  I bet they are, given the favorable terms of the settlement for BOA.


Luckily, there is a fairness hearing set for July.  Maybe someone can step forward and convince U.S. District Judge Thomas Russell of Kentucky to stop this lunacy and reinstate the lawsuit so the injured consumers can get some real relief.

November 08, 2009

Data breach victims four times more likely to be victims of identity theft

According to a recent study called "Data Breach Notifications: Victims Face Four Tmes Higher Risk of Fraud", those individuals whose information is exposed via a data breach are four times more likely to have their identity stolen than the average person.  The results of this study are contrary to the party line spewed by most companies that victims of their data breaches typically are not later victimized by fraudsters or identity thieves.  The study, conducted by Javelin Research, also underscores the need for stronger legislation to protect individuals from data breaches and require notification when data breaches occur.  As I posted earlier, the Senate Judiciary Committee has approved two such bills - S. 139 and S. 1490.

The study utilized multiple years of data including 2009 data breaches. The report also presents a timeline overview of the most recent and egregious data breaches in U.S. history, with recommendations for how individuals and companies can increase safety.

Possible new law on the horizon regarding data breaches?

On November 5, the Senate Judiciary Committee approved two bills regarding data security.  The first is Senator Feinstein's Data Breach Notification Act (S. 139).  The text of this proposed law can be found here - http://thomas.loc.gov/cgi-bin/query/z?c111:S.139:. 

The Data Breach Notification Act would greatly expand the amount of data combinations that, if breached, would require notification.  Currently, most laws only require notification if a name is released in conjunction with a Social Security number, driver's license number or financial account number.  If S. 139 is passed as is, it would require notification if only the first and last name, address/phone number and date of birth are stolen or inadvertantly released.  The bill would also require notification of the Department of Justice and fines up to $1000 per day per victim up to $1,000,000.

The second bill approved by the Senate Judiciary Committee was Senator Leahy's Personal Data Privacy and Security Act (S. 1490), the text of which can be found here - http://thomas.loc.gov/cgi-bin/query/z?c111:S.1490:.

Senator Leahy's bill goes beyond Senator Feinstein's in that it is styled to be proactive to prevent data breaches, rather than reactive to data breaches that have already occurred.  Think "Red Flag Rules" but with the emphasis on protecting against data breaches of any kind, rather than just recognizing and preventing identity theft.  The bill would require companies maintaining information on 10,000 or more United States persons to implement a comprehensive personal data privacy and security program that includes administrative, technical and physical safeguards to prevent data breaches as well as requiring employee training and vulnerability testing of the safeguards. 

I will do my best to follow these two bills and update you on their status.

October 07, 2009

21 Million Hotmail Users at Risk for Fraud

Do you use the Hotmail email service?  If so, you and 21 million others are at risk for fraud and potentially identity theft after a data breach led allowed users' password to be illegally obtained.

Hotmail users should all change their passwords and, after doing such, check their financial accounts and credit reports for any suspicious activity.

October 06, 2009

Potential data breach at National Archives puts 70 million veterans at risk of identity theft

The inspector general of the National Archives and Records Administration is investigating a potential data breach which puts the identities of 70 million veterans at risk.  Apparently, the agency sent a defective hard drive back to its vendor for repair without first destroying the data it contained.  The vendor determined that the drive was faulty and sent it out for recycling, with the records of approximately 70 million veterans still on it. 

The AWOL hard drive, reportedly worth approximately $2,000, is now worth millions, possibly billions, to an identity thief.  The hard drive should have been destroyed and should never have left the hands of the government agency.

I assume the agency will alert the 70 million veterans put at risk that their identities may be compromised but I have not seen that in writing anywhere.  If any of you can confirm that the government is alerting the veterans that they are at risk, please let me know.  If any of you can send me a copy of the letter from the government regarding the breach (with the veteran's name and other personal identifiers redacted, of course), that would be great.  Also, veterans at risk, please read the other posts on my site for what I hope to be helpful advice in discovering and countering any theft of your identity.  And, as always, contact me via ckittell@merkel-cocke.com, if you need my help or advice.

September 13, 2009

Ameritrade settlement one step closer to approval

Six million customers and former customers of Ameritrade (of which I am one) will unfortuantely have to wait a little while longer to learn if the proposed settlement regarding the theft of their personal information will be approved.  A hearing was held before U.S. District Judge Vaughn Walker in San Francisco on Thursday.  Judge Walker, who gave preliminary approval to the settlement way back in May, took the issue under advisement and will issue his ruling at a later date.  No indication as to how much later that date is going to be.

Anyone who either provided an e-mail address to Ameritrade or held an account there before September 14, 2007 will be able to benefit from the settlement.  Unfortunately, even if the settlement is approved, that doesn't mean much to you, me and the rest of the 6 million affected.  The settlement will pay nearly $1.9 million to the attorneys for legal fees.  I have little problem with the amount of attorneys' fees, except for the fact that the plaintiffs will get zip, nada, nothing in the way of cash.  The plaintiffs will receive one year of anti-spam software.  Woop-tee-doo.  Does anyone else think the plaintiffs should at least get enough to buy a happy meal?! 

While I realize the whole point of class actions is stop many little wrongs that, taken alone, are not worth the cost of correcting, but c'mon, the attorneys get $1.9 million and the plaintiffs don't get $.01?  Doesn't sound fair to me.  I have never handled a class action but I know and have worked with attorneys who have.  A tremendous amount of work goes into handling any litigation, but especially a class action.  But still ... shouldn't the injured parties get SOME kind of financial consideration?  I would suspect that most of the 6 million already have anti spam or, if they don't, its because they don't care to have anti-spam software.  So the offer is pretty much worth $0 to most of the 6 million, or so I would suspect.  Pretty crappy, if you ask me.

I have settled cases in the past where I ended up with more than my client, but its usually because I sunk a lot of my own cash into expenses in the case that I was not guaranteed to get back.  When the case settled, I got my percentage plus reimbursement of my expenses, which in some case nets me more of the final settlement but only because I have put my money at risk rather than my client's.  But I have never settled a case where my client got nothing in the way of compensation.  And I hope I never will.

September 03, 2009

TJX settles identity theft suit but NOT with victims of identity theft!

TJX agreed to pay $525,000 to settle an identity theft suit filed against it.  The payment goes NOT to the consumers who eventually became identity theft victims due to TJX's negligence.  Instead, TJX is paying off several banks, primarily for reimbursement of their legal expenses.

The data breach at issue involved at least 45 million card numbers of customers at TJX’s stores, one of the largest breaches on record.  TJX denies liability for the data breach

Albert Gonzalez, the computer hacker accused of masterminding the identity theft ring that hit TJX and other retailers, agreed to plead guilty just this past week.

August 22, 2009

$22 million identity theft scam involving AT&T and T-Mobile

Dan Goodin writes about how current and former cell phone dealers accessed the databases of AT&T and T-Mobile and stole the personal identifiers of customers in a four year identity theft scheme. Here's a quote from his article:

"Federal prosecutors have accused eight individuals of fraudulently obtaining $22m worth of wireless devices and services from AT&T and T-Mobile in an elaborate four-year scheme that exploited weaknesses in the cellular providers' network.

Between 2005 and July this year, two of the defendants used their status as current or former authorized cell phone dealers to tap in to databases maintained by AT&T and T-Mobile, according to an indictment unsealed earlier this week in federal court in Brooklyn, New York. They then stole the names, addresses and personally identifying information of cellular customers."