Custom Search
Showing posts with label fraud alerts. Show all posts
Showing posts with label fraud alerts. Show all posts

August 25, 2009

Ruling on the way in Experian v. LifeLock


In the battle of the titans ... er, I mean, titanic failures of consumer protection, we can expect a ruling soon. This case is like Darth Vader taking on the Witch King from the Lord of the Rings, or Dr. Doom v. The Joker or Dr. Kevorkian v. Michael Jackson's doctor ... bad guy v. bad guy (or, in the case of Experian v. LifeLock, maybe bad guy v. bad buy?) Anyway, word has it that a ruling is on the way ...

From the Arizona Republic at - http://www.azcentral.com/arizonarepublic/business/articles/2009/08/24/20090824biz-lifelock0825.html

"A U.S. District Court judge in the Central District of California is expected to rule this week on competing motions in a legal battle between credit bureau Experian and Tempe-based identity-theft protection firm LifeLock Inc.

Judge Andrew Guilford partially sided with Experian in May when he ruled LifeLock's practice of enrolling consumers in 90-day fraud alerts with the three main credit bureaus violates the Fair Credit Reporting Act. Experian argues that the law does not allow corporations to set the alerts on consumers' behalf.

In response, Experian sought a permanent injunction against LifeLock's practice, and LifeLock asked Guilford to reconsider his initial ruling. A hearing on both motions took place Monday in Santa Ana, Calif."

Doubt the judge will change his mind, but you never know. As for me, I'm siding with Hannibal Lecter ... I mean Experian, since I don't agree with anyone (corporation, person, puppy) placing a fraud alert on their credit report when there is not even a hint of an allegation of fraud.

July 08, 2009

15 U.S.C. 1681c-1 - part 3

I conclude my explanation of 15 U.S.C. 1681c-1 of the Fair Credit Reporting Act.

"(g) Duty of other consumer reporting agencies to provide contact information. If a consumer contacts any consumer reporting agency that is not described in section 603(p) to communicate a suspicion that the consumer has been or is about to become a victim of fraud or related crime, including identity theft, the agency shall provide information to the consumer on how to contact the Commission and the consumer reporting agencies described in section 603(p) to obtain more detailed information and request alerts under this section."

[This means that if a consumer tells a non-national credit bureau (i.e. one of the ones that are not part of the "big 3" credit bureaus of Experian, Equifax and Trans Union) that he suspects he is a victim of fraud, identity theft or a related crime, this credit bureau must tell the consumer how to contact the FTC and the big three credit bureaus so he or she can obtain more detailed information and ask for fraud or active duty alerts as provided for by 1681c-1.]

"(h) Limitations on Use of Information for Credit Extensions

(1) Requirements for initial and active duty alerts -

(A) Notification. Each initial fraud alert and active duty alert under this section shall include information that notifies all prospective users of a consumer report on the consumer to which the alert relates that the consumer does not authorize the establishment of any new credit plan or extension of credit, other than under an open-end credit plan (as defined in section 103(i)), in the name of the consumer, or issuance of an additional card or an existing credit account requested by a consumer, or any increase in credit limit on an existing credit account requested by a consumer, except in accordance with subparagraph (B).

(B) Limitation on Users

(i) In general. No prospective user of a consumer report that includes an initial fraud alert or an active duty alert in accordance with this section may establish a new credit plan or extension of credit, other than under an open-end credit plan (as defined in section 103(i)), in the name of the consumer, or issue an additional card on an existing credit account requested by a consumer, or grant any increase in credit limit on an existing credit account requested by a consumer, unless the user utilizes reasonable policies and procedures to form a reasonable belief that the user knows the identity of the person making the request.

(ii) Verification. If a consumer requesting the alert has specified a telephone number to be used for identity verification purposes, before authorizing any new credit plan or extension described in clause (i) in the name of such consumer, a user of such consumer report shall contact the consumer using that telephone number or take reasonable steps to verify the consumer's identity and confirm that the application for a new credit plan is not the result of identity theft."

[This section is directed at users of credit reports, i.e. the company pulling the consumer's credit report for one of the permissible purposes identified in 1681b. If the consumer has an initial fraud alert or an active duty alert on his credit report, the user can not grant new credit or provide a new card or grant a credit limit increase unless the user uses reasonable procedures to verify that it does indeed know who is making the request. Further, if the consumer has provided a phone number, the user must contact the consumer using the phone number or take reasonable steps to verify the consumer's identity and that the applicant is not an identity thief. While "reasonable steps" is not defined, I would think it would mean what a reasonable person would do under like or similar circumstances.]

"(2) Requirements for Extended Alerts

(A) Notification. Each extended alert under this section shall include information that provides all prospective users of a consumer report relating to a consumer with -

(i) notification that the consumer does not authorize the establishment of any new credit plan or extension of credit described in clause (i), other than under an open-end credit plan (as defined in section 103(i)), in the name of the consumer, or issuance of an additional card on an existing credit account requested by a consumer, or any increase in credit limit on an existing credit account requested by a consumer, except in accordance with subparagraph (B); and

(ii) a telephone number or other reasonable contact method designated by the consumer.

(B) Limitations on users. No prospective user of a consumer report or of a credit score generated using the information in the file of a consumer that includes an extended fraud alert in accordance with this section may establish a new credit plan or extension of credit, other than under an open-end credit plan (as defined in section 103(i)), in the name of the consumer, or issue an additional card on an existing credit account requested by a consumer, or any increase in credit limit on an existing credit account requested by a consumer, unless the user contacts the consumer in person or using the contact method described in subparagraph (A)(ii) to confirm that the application for a new credit plan or increase in credit limit, or request for an additional card is not the result of identity theft."

[This is (1) except that a contact phone number or other reasonable contact method is required and the user is required to use that phone number or contact method to confirm that the applicant is not an identity thief.]

That concludes my explanation of 15 U.S.C. 1681c-1 of the Fair Credit Reporting Act. I will start explaining 15 U.S.C. 1681c-2 in the next installment.

June 21, 2009

15 U.S.C. 1681c-1 - part 2

This is part 2 of my explanation of 15 U.S.C. 1681c-1 of the Fair Credit Reporting Act.

"(c) Active duty alerts. Upon the direct request of an active duty military consumer, or an individual acting on behalf of or as a personal representative of an active duty military consumer, a consumer reporting agency described in section 603(p) [15 U.S.C. 1681a(p)] that maintains a file on the active duty military consumer and has received appropriate proof of the identity of the requester shall --

(1) include an active duty alert in the file of that active duty military consumer, and also provide that alert along with any credit score generated in using that file, during a period of not less than 12 months, or such longer period as the Commission shall determine, by regulation, beginning on the date of the request, unless the active duty military consumer or such representative requests that such fraud alert be removed before the end of such period, and the agency has received appropriate proof of the identity of the requester for such purpose;

(2) during the 2-year period beginning on the date of such request, exclude the active duty military consumer from any list of consumers prepared by the consumer reporting agency and provided to any third party to offer credit or insurance to the consumer as part of a transaction that was not initiated by the consumer, unless the consumer requests that such exclusion be rescinded before the end of such period; and

(3) refer the information regarding the active duty alert to each of the other consumer reporting agencies described in section 603(p), in accordance with procedures developed under section 621(f)."

[This subsection requires a consumer reporting agency that is made aware of the active military duty status of a consumer (and confirms the consumer's identity) to include an active military duty alert on the consumer's credit reports at least for a year, longer if the Federal Trade Commission decides it should be longer. Also, for the first two years of any active duty alert, the credit bureaus must exclude the military consumer from the lists of consumers they provide to third parties for offers of credit or insurance. I do not think subsection (1) is supposed to refer to this alert as a "fraud alert", since it is actually an active duty alert which does not mean any fraud has occurred or is suspected of occurring.]

"(d) Procedures. Each consumer reporting agency described in section 603(p) shall establish policies and procedures to comply with this section, including procedures that inform consumers of the availability of initial, extended, and active duty alerts and procedures that allow consumers and active duty military consumers to request initial, extended, or active duty alerts (as applicable) in a simple and easy manner, including by telephone."

[This subsection requires the credit bureaus to come up with procedures to make consumers aware of the two types of fraud alerts (i.e. the 90 day initial alert and the 7 year extended alert) as well as the active duty alert.]

"(e) Referrals of alerts. Each consumer reporting agency described in section 603(p) that receives a referral of a fraud alert or active duty alert from another consumer reporting agency pursuant to this section shall, as though the agency received the request from the consumer directly, follow the procedures required under --

(1) paragraphs (1)(A) and (2) of subsection (a), in the case of a referral under subsection (a)(1)(B);

(2) paragraphs (1)(A), (1)(B), and (2) of subsection (b), in the case of a referral under subsection (b)(1)(C); and

(3) paragraphs (1) and (2) of subsection (c), in the case of a referral under subsection (c)(3)."

[This subsection applies where a consumer reporting agency that did not receive the original notification of a fraud alert or active duty alert receives notification of such alert from the credit bureau that did receive the initial request for an alert. In that instance, the credit bureau must comply with the subsections listed just like it had received the original request for an alert.]

"(f) Duty of reseller to reconvey alert. A reseller shall include in its report any fraud alert or active duty alert placed in the file of a consumer pursuant to this section by another consumer reporting agency."

[This section just requires a reseller of credit information to include the fraud alert or active duty alert on the credit report it compiles and resells.]

I should be able to finish with my explanation of 15 U.S.C. 1681c-1 in part 3.

15 U.S.C. 1681c-1

Today, I begin my explanation of 15 U.S.C. 1681c-1 of the Fair Credit Reporting Act.

"15 U.S.C. 1681c-1. Identity theft prevention; fraud alerts and active duty alerts.

(a) One-call Fraud Alerts

(1) Initial alerts. Upon the direct request of a consumer, or an individual acting on behalf of or as a personal representative of a consumer, who asserts in good faith a suspicion that the consumer has been or is about to become a victim of fraud or related crime, including identity theft, a consumer reporting agency described in section 603(p) [15 U.S.C. 1681a(p)] that maintains a file on the consumer and has received appropriate proof of the identity of the requester shall --

(A) include a fraud alert in the file of that consumer, and also provide that alert along with any credit score generated in using that file, for a period of not less than 90 days, beginning on the date of such request, unless the consumer or such representative requests that such fraud alert be removed before the end of such period, and the agency has received appropriate proof of the identity of the requester for such purpose; and

(B) refer the information regarding the fraud alert under this paragraph to each of the other consumer reporting agencies described in section 603(p), in accordance with procedures developed under section 621(f)."

[This section requires the consumer reporting agency to report a fraud alert as part of a consumer's credit report for 90 days after the request for the fraud alert is made, assuming the consumer reporting agency receives sufficient proof of the identity of the person requesting the fraud alert. The person requesting the fraud alert must have a good faith suspicion that he or she is either a fraud victim or is about to become a fraud victim. This is the problem with the way LifeLock used to do business since it requested fraud alerts for all its customers, regardless of whether they were either fraud victims or thought they were about to be fraud victims.

The consumer reporting agency that receives the request for a fraud alert must also relay the fraud alert to the other consumer reporting agencies.]

"(2) Access to free reports. In any case in which a consumer reporting agency includes a fraud alert in the file of a consumer pursuant ot this subsection, the consumer reporting agency shall --

(A) disclose to the consumer that the consumer may request a free copy of the file of the consumer pursuant to section 612(d); and

(B) provide to the consumer all disclosures required to be made under section 609, without charge to the consumer, not later than 3 business days after any request described in subparagraph (A)."

[This subsection requires the consumer reporting agency to tell the consumer that requests a fraud alert that he or she is entitled to a free copy of his or her credit file (i.e. his or her credit report) and provide all disclosures required by section 609 (which we will get to eventually). Oddly enough, I don't think I have ever seen a credit bureau tell a consumer who requested a fraud alert that he can have a free credit report.]

"(b) Extended Alerts

(1) In general. Upon the direct request of a consumer, or an individual acting on behalf of or as a personal representative of a consumer, who submits an identity theft report to a consumer reporting agency described in section 603(p) that maintains a file on the consumer, if the agency has received appropriate proof of the identity of the requester, the agency shall --

(A) include a fraud alert in the file of that consumer, and also provide that alert along with any credit score generated in using that file, during the 7-year period beginning on the date of such request, unless the consumer or such representative requests that such fraud alert be removed before the end of such period and the agency has received appropriate proof of the identity of the requester for such purpose;

(B) during the 5-year period beginning on the date of such request, exclude the consumer from any list of consumers prepared by the consumer reporting agency and provided to any third party to offer credit or insurance to the consumer as part of a transaction that was not initiated by the consumer, unless the consumer or such representative requests that such exclusion be rescinded before the end of such period; and

(C) refer the information regarding the extended fraud alert under this paragraph to each of the other consumer reporting agencies described in section 603(p), in accordance with procedures developed under section 621(f)."

[This section requires the consumer reporting agency to add a fraud alert to a consumer's credit report for 7 years if the consumer requests it and provides an identity theft report. The credit bureau must also remove the consumer's name for five years from any list of consumers prepared by the credit bureau and provided to a third party regarding an offer of credit or insurance.]

"(2) Access to free reports. In any case in which a consumer reporting agency includes a fraud alert in the file of a consumer pursuant to this subsection, the consumer reporting agency shall --

(A) disclose to the consumer that the consumer may request 2 free copies of the file of the consumer pursuant to section 612(d) during the 12-month period beginning on the date on which the fraud alert was included in the file; and

(B) provide to the consumer all disclosures required to be made under section 609, without charge to the consumer, not later than 3 business days after any request described in subparagraph (A)."

[Subsection (2) requires the credit bureau who added a fraud alert regarding the consumer to tell the consumer that he or she is entitled to two free credit reports during the first 12 months of the fraud alert. Again, I have never seen a credit bureau comply with this section.]

I will continue my explanation of 15 U.S.C. 1681c-1 with subsection (c) in part 2.

June 01, 2009

Another article about LifeLock

Here's another article about the California Federal Court's ruling that LifeLock must stop requesting fraud alerts for its customers. This article is from The Columbus Dispatch and indicates that the price of identity theft protection may rise.

FRAUD-ALERT LAWSUIT
Cost of ID theft protection could be about to rise
Monday, June 1, 2009 6:23 AM

SAN JOSE, Calif. - Companies that sell "identity theft protection" present an alluring but questionable proposition.

For as much as about $100 per year, the main thing they do is set fraud alerts that force banks to call people before new lines of credit are opened in their name. The alerts can be useful - but people can set them themselves, at no cost.

Now even that function could be taken away from the ID theft-prevention services.
A federal court in California has blocked Tempe, Ariz.-based Life-Lock, one of the industry's biggest players, from setting fraud alerts with Experian, one of the three main credit-reporting agencies that manage the fraud alerts.

Experian is suing LifeLock, claiming that LifeLock's automatic renewal of customers' fraud alerts - which happens every 90 days, when they expire - costs Experian millions of dollars in processing expenses.

In a ruling last week, a judge agreed with one of Experian's central arguments: that LifeLock isn't authorized to set alerts for consumers, and that federal law requires consumers to set alerts themselves by contacting credit bureaus directly.

The ruling has caused at least one ID theft prevention service, Debix, to announce that it plans to drop fraud alerts and offer credit-monitoring instead. The trend is likely to play out across the industry.

"It's going to be a game-changer," said Jay Foley, executive director of the Identity Theft Resource Center, a nonprofit organization based in San Diego.

For consumers, this means "identity theft protection" services could get more expensive - and less useful. Credit-monitoring services can cost $180 a year, and they don't always detect a fraud.

In contrast, fraud alerts are supposed to make it much harder for identity theft to be pulled off in the first place.

When a bank or retailer runs a credit check on someone for a new account, if a fraud alert pops up, the bank or retailer is required to call that person or use any other "reasonable policies and procedures" to verify their identity. That is meant to stop a scammer who goes into a retail store and tries, for example, to get instant credit under someone else's name and then walk out with a TV the other guy would be on the hook for.

LifeLock's chief executive, Todd Davis, who is known for plastering his Social Security number on billboards in an advertising gimmick, says his company will fight the court ruling and won't stop setting fraud alerts with the other two credit bureaus, Equifax and TransUnion.
Placing an alert at one bureau means an alert is placed at all three, because they have to notify one another.

"It's going to be business as usual until we hear they don't agree with the way we're interpreting this," Davis said. "We're not worried that this is some catastrophic decision."
At least one of his competitors disagrees.

Bo Holland, the founder of Debix, which offers ID theft protection for $24 a year, said his company will now stop setting fraud alerts and sell credit-monitoring instead. Holland said many of Debix's clients are corporations that subsidize the service for employees and customers after a breach.

Losing the ability to set fraud alerts is "definitely a step backward. It's been a very effective mechanism; creditors did a pretty good job of doing what they were supposed to do," he said. "Absolutely, I'm sad to see it go."

Holland noted, though, that fraud alerts have weaknesses, because banks will sometimes ask "security questions" of credit applicants instead of calling a consumer before opening a new account. If criminals have enough personal information about their victims, the con artists might be able to answer those questions, and the consumer would never get a call.

Representatives for another big ID theft protection service, TrustedID (which costs around $100 a year), did not return messages seeking comment.

Experian's lawsuit is not the first against LifeLock. Some customers have sued, saying they were misled about their level of protection.

The main thing that services such as LifeLock guard against is credit fraud. But there are other types of fraud, such as using someone's Social Security number to get a job or medical coverage, or giving it to police to impersonate someone who is innocent. A fraud alert on a credit report is powerless against those crimes.