Custom Search

June 09, 2009

Today's presentation at the Clarksdale Rotary Club

I'm pleased to announce that I spoke today at the Clarksdale Mississippi Rotary Club regarding the Fair Credit Reporting Act. I very much enjoyed speaking to my home town people about representing victims of credit reporting errors on a national basis. I gave them the basics about the Fair Credit Reporting Act and showed them a PowerPoint presentation regarding a mixed file case I handled against Equifax several years ago. Very fun and, I hope, very informative for the Club.

Good article about Identity Theft

Joe Campana at the Identity Theft Examiner has a good article about what to do about identity theft. The article starts off as follows:

"'Identity theft' elicits different reactions—apathy, fear or concern. The apathetic are typically those who do not understand what identity theft is and how identity thieves can victimize them. Often, the fearful are those that neither understand how to control their fate as victims or how to take preventive steps to control their destiny. The concerned generally understand the crime, how to prevent it and keep identity theft on their personal radar."

Campana then goes on to make five suggestions about what you can do about identity theft. Read the rest of the article at http://www.examiner.com/x-9215-Identity-Theft-Examiner~y2009m6d8-Identity-theftwhat-you-can-do#fragment-7.

June 07, 2009

What to do if you suspect your identity was stolen

If you suspect your identity was stolen, how can you find out for sure? What steps should you take?

I have been representing identity theft victims for nearly 10 years now and this is what I tell potential clients who call me with suspicions that their identities have been stolen.

First, obtain your credit reports from Experian, Equifax and Trans Union. When you receive your credit reports, the first place to look is the inquiry section of the credit report, which is towards the end of the report. An inquiry is a notation of each access to your credit report, so if someone obtains your credit report, the corresponding inquiry will tell you who obtained it and when.

The inquiry section on a "consumer disclosure" (which is what the credit bureaus call the credit report they provide directly to the consumer and not a third party) is usually separated into two sections - inquiries seen by third parties and inquiries only seen by the consumer. The inquiries seen by third parties are generally initiated by the consumer when he or she applies for credit, insurance, etc. I call these hard inquiries. There are also soft inquiries, the kind that do not show up on credit reports provided to third parties but are shown on the consumer disclosures sent to consumers. These include promotional inquiries (think for junk mail purposes), and accesses by the credit bureau when they edit the consumer's credit report. Also, account reviews conducted by existing creditors are soft inquiries.

If you suspect you are a victim of identity theft, you should first look to the hard inquiries. You should recognize all of these inquiries as related to credit transactions that you initiated. If you do not recognize them, they were probably initiated by someone else ... i.e. the identity thief. You should then contact the creditors identified in those inquiries and find out what prompted the inquiry and, if it was indeed a credit application that you did not submit, then you are the victim of identity theft.

Your first step should be to obtain a police report regarding the theft of your identity. Start with your local police. If they won't take the report (i.e. because the crime occurred outside their jurisdiction, perhaps), then try to get a police report from the police where the identity theft occurred, if you know where that is. If you can do neither, you can make an identity theft report with the U.S. Postal Inspector by going to any post office. Your police report and/or identity theft report should identify the fraud accounts of which you are aware.

Each creditor that allowed the identity thief to open an account using your name and/or social security number should have procedures for reporting the opening of the fraudulent account. Technically, you do not have to follow their procedures, since under the Fair Credit Reporting Act, the duty of a creditor to investigate a dispute of identity theft only arises when a dispute is made to the credit bureau(s) which are reporting the fraudulent account(s). However, it is a good idea to comply as fully as possible with the fraudulent credit grantor for two reasons. First, if their procedures work, the fraudulent account should be removed from your credit report and you should be done with it forever. Second, should the fraudulent credit grantors fail to remove the fraud accounts from your credit report, they can not complain in defense of your eventual FCRA lawsuit that they would have removed the fraud account had you simply complied with their procedures.

Also, you need to be sure to dispute the fraud accounts to the fraudulent credit grantors in writing, even if their procedures do not require it and even if you have already disputed the accounts verbally. Make sure your written dispute includes as much detail and proof regarding the theft of your identity as you can. Even though these disputes directly to the fraudulent credit grantors do not trigger any duty under the FCRA, they are important to provide a history for the credit grantor when you do make a dispute that triggers the credit grantor's duty to reasonably investigate your dispute.

After you have disputed the fraud accounts to the fraudulent credit grantors in writing, you should also send written disputes to the credit bureaus disputing the inclusion of the fraud accounts on your credit reports. This triggers two duties on the part of the credit bureau. First, they must perform a reasonable investigation of your dispute. Second, they must forward your dispute and "all relevant information" to the fraudulent credit grantor, which triggers the credit grantor's duty to perform a reasonable investigation of the dispute. This is why it is important for you to have already disputed the fraud account to the credit grantor, so the credit grantor can not argue that the credit bureau did not supply it with sufficient information to reasonably investigate the dispute.

The credit bureau must report the results of the investigation to you within 30 days of the dispute.

The best advice I can give you is to be diligent and persistent. If the credit bureau does not fix your credit report after the first dispute, dispute again. Provide more detail. Provide more proof. And if that doesn't work, dispute again. The more chances you give the credit bureaus and credit grantors to remove the fraudulent accounts, the more likely they will do it and, if they don't, the better your eventual FCRA lawsuit will be.

If you have any questions or are an identity theft victim in need of help, please feel free to contact me through comments or directly at ckittell@merkel-cocke.com.

June 06, 2009

15 U.S.C. 1681b - part 3

Now, moving on to explain subsection (c) to 15 U.S.C. 1681b of the Fair Credit Reporting Act:

"(c) Furnishing reports in connection with credit or insurance transactions that are not initiated by the consumer.

(1) In general. A consumer reporting agency may furnish a consumer report relating to any consumer pursuant to subparagraph (A) or (C) of subsection (a)(3) in connection with any credit or insurance transaction that is not initiated by the consumer only if

(A) the consumer authorizes the agency to provide such report to such person; or

(B)(i) the transaction consists of a firm offer of credit or insurance;

(ii) the consumer reporting agency has complied with subsection (e); and

(iii) there is not in effect an election by the consumer, made in accordance with subsection (e), to have the consumer's name and address excluded from lists of names provided by the agency pursuant to this paragraph."

[This means that, when the consumer does not initiate the transaction that forms the basis for the request for the credit report, the credit bureau may only provide the consumer report to a third party if the consumer consents to the disclosure or if there is a firm offer of credit or insurance, the consumer reporting agency has complied with 15 U.S.C. 1681b(e) (more on that in the next post) and, the consumer has not opted out of pre-screening lists (i.e. the consumer has taken his or her name off the list of consumers who accept preapproved offers). If the consumer did not initiate the transaction and neither of the two other exceptions apply, then there is no permissible purpose for the disclosure of the consumer report.]

"(2) Limits on information received under paragraph (1)(B). A person may receive pursuant to paragraph (1)(B) only

(A) the name and address of a consumer;

(B) an identifier that is not unique to the consumer and that is used by the person solely for the purpose of verifying the identity of the consumer; and

(C) other information pertaining to a consumer that does not identify the relationship or experience of the consumer with respect to a particular creditor or other entity."

[So if the consumer neither initiates the transaction nor consents to the credit report's disclosure (i.e. when the basis for the consumer report's disclosure is that there was a firm offer of credit or insurance), the credit bureau can not disclose the whole consumer report but is only allowed to disclose the name and address of the consumer and other non-credit related information. In other words, the credit bureau returns a list of names and addresses of consumers who meet the criteria provided by the company requesting the credit report.]

"(3) Information regarding inquiries. Except as provided in section 609(a)(5) [1681g], a consumer reporting agency shall not furnish to any person a record of inquiries in connection with a credit or insurance transaction that is not initiated by a consumer."

[In addition to not being able to produce credit information, subsection (3) makes it clear that the consumer reporting agency can not furnish the record of inquiries (i.e. the list of companies receiving that consumer's credit report within the last two years) when the transaction is not initiated by the consumer.]

"(d) Reserved."

[Hey, an easy one. This subsection is reserved for any later amendment to 1681b.]

I will move on to subsection (e) of 15 U.S.C. 1681b in part 4's explanation. Thanks for reading.

Class action against Ameritrade potentially involving identity theft

I am a plaintiff and didn't even know it. I received a class action settlement notice in the mail yesterday regarding a class action filed in the Northern District of California, San Francisco division (odd how I've never been in the San Francisco area but they have personal jurisdiction over me in a case that I didn't even know I was involved in filed by attorneys I do not know much less hire, but I digress). The suit alleges that an authorized third party obtained Ameritrade's e-mail addresses of its stock holders and then used them to send spam and possibly commit identity theft. The complaint seeks monetary and injunctive relief.

Unfortunately, the class action lawyers forgot that they were supposed to be seeking monetary awards for their clients (me included) too. Instead, the proposed settlement includes a one year, free subscription to an anti-spam Internet security software product, a warning on Ameritrade's website concerning stock touting spam (shouldn't the lawsuit itself have prompted such a warning?!), an independent consultant to conduct additional analysis as to whether the personal information of any class action member has been subject to "organized misuse" including identity theft (like people who have their identities stolen really want to allow another third party to sift through their personal information?) and general customer support about the "benefits" of the settlement (so one of my benefits is to get to ask questions about the other stuff I don't want but am getting?).

This has to be the lamest class action settlement I have ever seen. Congrats to Ameritrade's lawyers on snowing the class action attorneys so bad. Usually the class's attorneys' names would appear on the notice of settlement, but not this time. I wouldn't want my name associated with such a terrible outcome either.

There is hope though. Class members such as me can either opt out by July 9 or the settlement could be found to be unfair at the fairness hearing on September 10. Why I have to opt out before I know whether the settlement is going to be approved seems a bit unfair. What happens if I opt out and then the Court finds that the settlement is not fair and orders the parties to try again and, this time, class action attorneys actually do their job and secure a fair settlement with some value to it for the actual members of the class, not just their counsel that they didn't get to choose themselves?

I, for one, am going to opt out. But I hope that someone challenges this settlement on behalf of the class.

June 05, 2009

15 U.S.C. 1681b - part 2

Now, to continue our discussion of 15 U.S.C. 1681b - the permissible purposes section of the Fair Credit Reporting Act - I will discuss subsection (b) of 1681b.

"(b) Conditions for Furnishing and Using Consumer Reports for Employment Purposes.

(1) Certification from user. A consumer reporting agency may furnish a consumer report for employment purposes only if

(A) the person who obtains such report from the agency certifies to the agency that

(i) the person has complied with paragraph (2) with respect to the consumer report, and the person will comply with paragraph (3) with respect to the consumer report if paragraph (3) becomes applicable; and

(ii) information from the consumer report will not be used in violation of any applicable Federal or State equal employment opportunity law or regulation; and"

(B) the consumer reporting agency provides with the report, or has previously provided, a summary of the consumer's rights under this title, as prescribed by the Federal Trade Commission under section 609(c)(3) [§ 1681g]."

[In other words, the user (i.e. the person or company receiving the credit report) must certify that he has complied with paragraph 2's requirements to disclose to the consumer that a credit report may be obtained and that the user has written authorization from the consumer to obtain the credit report, and, the user (i.e. the prospective employer) must certify that, if it denies the employment application or the prospective employee suffers some other adverse action as a result of his or her credit report (i.e. paragraph 3), the user will provide a copy of the credit report to the consumer along with a description of his or her rights as a consumer. The user must also certify that the credit report will not be used in violation of any equal employment opportunity law or regulation and must provide a summary of the consumer's rights under the FCRA.]

"(2) Disclosure to Consumer.

(A) In general. Except as provided in subparagraph (B), a person may not procure a consumer report, or cause a consumer report to be procured, for employment purposes with respect to any consumer, unless--

(i) a clear and conspicuous disclosure has been made in writing to the consumer at any time before the report is procured or caused to be procured, in a document that consists solely of the disclosure, that a consumer report may be obtained for employment purposes; and

(ii) the consumer has authorized in writing (which authorization may be made on the document referred to in clause (i)) the procurement of the report by that person."

[Before a prospective employer (or current employer using a credit report to make a decision about the current employee) may obtain a consumer's credit report to use in an employment decision, the employer must make "clear and conspicuous" disclosure to the consumer in writing that a credit report may be obtained for employment purposes, and must receive written authorization from the consumer for the employer to get the consumer's credit report.]

"(B) Application by mail, telephone, computer, or other similar means. If a consumer described in subparagraph (C) applies for employment by mail, telephone, computer, or other similar means, at any time before a consumer report is procured or caused to be procured in connection with that application--

(i) the person who procures the consumer report on the consumer for employment purposes shall provide to the consumer, by oral, written, or electronic means, notice that a consumer report may be obtained for employment purposes, and a summary of the consumer's rights under section 615(a)(3); and

(ii) the consumer shall have consented, orally, in writing, or electronically to the procurement of the report by that person."

[If the possible employee does not apply in person, the employer must still disclose that a credit report may be obtained, provide a summary of the consumer's rights and get the consumer's consent. However, unlike an in person employment decision, consent may be obtained orally and not just in writing. Also, as you can see from (C) below, this only applies to positions under the Secretary of Transportation's regulations and there has not been any previous in-person contact between consumer and prospective employer.]

"(C) Scope. Subparagraph (B) shall apply to a person procuring a consumer report on a consumer in connection with the consumer's application for employment only if--

(i) the consumer is applying for a position over which the Secretary of Transportation has the power to establish qualifications and maximum hours of service pursuant to the provisions of section 31502 of title 49, or a position subject to safety regulation by a State transportation agency; and

(ii) as of the time at which the person procures the report or causes the report to be procured the only interaction between the consumer and the person in connection with that employment application has been by mail, telephone, computer, or other similar means."

[Told you, (C) limits (B) to applications for positions under the Secretary of Transportation's regulations where there has not been any previous in-person contact between consumer and prospective employer.]

"(3) Conditions on use for adverse actions.

(A) In general. Except as provided in subparagraph (B), in using a consumer report for employment purposes, before taking any adverse action based in whole or in part on the report, the person intending to take such adverse action shall provide to the consumer to whom the report relates--

(i) a copy of the report; and

(ii) a description in writing of the rights of the consumer under this title, as prescribed by the Federal Trade Commission under section 609(c)(3)."

[So if the employer refuses to hire the consumer, or demotes him or her if a current employee, based upon the content of the consumer's credit report, the employer must provide the consumer with a copy of his or her credit report and a description of the rights of the consumer pursuant to the FCRA.]

"(B) Application by mail, telephone, computer, or other similar means.

(i) If a consumer described in subparagraph (C) applies for employment by mail, telephone, computer, or other similar means, and if a person who has procured a consumer report on the consumer for employment purposes takes adverse action on the employment application based in whole or in part on the report, then the person must provide to the consumer to whom the report relates, in lieu of the notices required under subparagraph (A) of this section and under section 615(a), within 3 business days of taking such action, an oral, written or electronic notification--

(I) that adverse action has been taken based in whole or in part on a consumer report received from a consumer reporting agency;

(II) of the name, address and telephone number of the consumer reporting agency that furnished the consumer report (including a toll-free telephone number established by the agency if the agency compiles and maintains files on consumers on a nationwide basis);

(III) that the consumer reporting agency did not make the decision to take the adverse action and is unable to provide to the consumer the specific reasons why the adverse action was taken; and

(IV) that the consumer may, upon providing proper identification, request a free copy of a report and may dispute with the consumer reporting agency the accuracy or completeness of any information in a report.

(ii) If, under clause (B)(i)(IV), the consumer requests a copy of a consumer report from the person who procured the report, then, within 3 business days of receiving the consumer's request, together with proper identification, the person must send or provide to the consumer a copy of a report and a copy of the consumer's rights as prescribed by the Federal Trade Commission under section 609(c)(3)."

[If the potential employee (or current employee if seeking a raise or promotion) does not apply in person and suffers an adverse action (i.e. does not get the job or is denied the promotion or raise), then the employer must give written notice to the consumer of the adverse action and must provide the identity and address of the consumer reporting agency that provided the credit report that the adverse action is based upon, tell the employee that the consumer reporting agency did not make the decision to deny the employment application (even though the consumer reporting agencies do provide the "denial codes" used by most users when denying credit or employment) and inform the consumer that he can obtain a free copy of the consumer report from the consumer reporting agency (but not from the prospective employer, which would make more sense since that is the actual consumer report used in the adverse action decision, unlike the credit report the credit bureau sends days or even weeks later that may have changed since the date of the adverse action) and that he can dispute to the credit bureau any inaccuracies on the credit report.]

"(C) Scope. Subparagraph (B) shall apply to a person procuring a consumer report on a consumer in connection with the consumer's application for employment only if--

(i) the consumer is applying for a position over which the Secretary of Transportation has the power to establish qualifications and maximum hours of service pursuant to the provisions of section 31502 of title 49, or a position subject to safety regulation by a State transportation agency; and

(ii) as of the time at which the person procures the report or causes the report to be procured the only interaction between the consumer and the person in connection with that employment application has been by mail, telephone, computer, or other similar means."

[Subsection (C) limits subsection (B) to only jobs that the Secretary of Transportation has authority over to establish qualifications and maximum hours or jobs subject to safety regulations from a State transportation agency and only such jobs that are not applied for in person.]

"(4) Exception for national security investigations.

(A) In general. In the case of an agency or department of the United States Government which seeks to obtain and use a consumer report for employment purposes, paragraph (3) shall not apply to any adverse action by such agency or department which is based in part on such consumer report, if the head of such agency or department makes a written finding that–

(i) the consumer report is relevant to a national security investigation of such agency or department;

(ii) the investigation is within the jurisdiction of such agency or department;

(iii) there is reason to believe that compliance with paragraph (3) will–

(I) endanger the life or physical safety of any person;

(II) result in flight from prosecution;

(III) result in the destruction of, or tampering with, evidence relevant to the investigation;

(IV) result in the intimidation of a potential witness relevant to the investigation;

(V) result in the compromise of classified information; or

(VI) otherwise seriously jeopardize or unduly delay the investigation or another official proceeding."

[In other words, if an agency or department of the United States government obtains and uses a consumer report when denying an employment application, the agency or department does not have to comply with the requirements of subsection (3) if the consumer report is relevant to a national security investigation, the investigation is within the purview of that particular agency or department, and there is "reason to believe" that the investigation would either put someone at risk, result in someone either fleeing prosecution or tampering with evidence (i.e. because they were prematurely put on notice of the investigation), result in a witness potentially being intimidated or classified information being compromised or (the catchall) otherwise risking or delaying the investigation or other official proceeding. These reasons are so broad and vague just about any fact pattern could be shoehorned into one of them.]

"(B) Notification of consumer upon conclusion of investigation. Upon the conclusion of a national security investigation described in subparagraph (A), or upon the determination that the exception under subparagraph (A) is no longer required for the reasons set forth in such subparagraph, the official exercising the authority in such subparagraph shall provide to the consumer who is the subject of the consumer report with regard to which such finding was made--

(i) a copy of such consumer report with any classified information redacted as necessary;

(ii) notice of any adverse action which is based, in part, on the consumer report; and

(iii) the identification with reasonable specificity of the nature of the investigation for which the consumer report was sought."

[Once either the investigation is over or the reason for keeping secret the fact that a credit report was obtained is no longer valid, the government agency or department must provide the consumer a copy of the credit report and provide notice of any adverse action and describe generally the nature of the investigation.]

"(C) Delegation by head of agency or department. For purposes of subparagraphs (A) and (B), the head of any agency or department of the United States Government may delegate his or her authorities under this paragraph to an official of such agency or department who has personnel security responsibilities and is a member of the Senior Executive Service or equivalent civilian or military rank."

[In other words, the head honcho of the agency or department can delegate his authority to a subordinate in his department of sufficient security clearance.]

"(D) Report to the Congress. Not later than January 31 of each year, the head of each agency and department of the United States Government that exercised authority under this paragraph during the preceding year shall submit a report to the Congress on the number of times the department or agency exercised such authority during the year.

(E) Definitions. For purposes of this paragraph, the following definitions shall apply:

(i) The term 'classified information' means information that is protected from unauthorized disclosure under Executive Order No. 12958 or successor orders."

[See http://www.fas.org/sgp/clinton/eo12958.html.]

"(ii) The term 'national security investigation' means any official inquiry by an agency or department of the United States Government to determine the eligibility of a consumer to receive access or continued access to classified information or to determine whether classified information has been lost or compromised."

[i.e. investigations to initiate or renew security clearances.]

I'll pick back up with subsection (c) in part 3 regarding 15 U.S.C. 1681b.

New phishing scam

What is "phishing", you might ask? According to wikipedia.org, it is "the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication."

The way it works is that you receive what looks like an e-mail from a trusted source, i.e. a bank, the IRS, etc. that says there is some problem (or in the case of the IRS, an unclaimed tax refund) and asks you to log in with your user name and password, which the phisher then steals. Or you could be asked to call a number and give your name, Social Security number, etc. to what you think is a legitimate business. Unfortunately, its not and you have just given away your private information.

I read an article this morning about a new phishing scam that's preying on the growing number of people looking for jobs. The articles says "FlexJobs, the leading website for legitimate telecommuting and online job listings, today cautioned jobseekers to beware of a new phishing email scam targeting jobseekers. This most recent email phishing scam involves asking jobseekers to fill out a credit report in order to gain access to the final interview stage for a job. The phishing email includes a link to a 'free credit report' that the employer has arranged for the jobseeker's convenience. Scammers are taking advantage of the high unemployment rate to contact people by email with deceptive offers for interviews and jobs. "

FlexJobs also warns jobseekers (and anyone else) to look out for:
  • "Unsolicited emails.
  • Emails from supposed employers but using free email domains (e.g., @yahoo.com, @gmail.com, @aol.com, or @hotmail.com) instead of one related to the company domain name.
  • Emails from individuals or companies the jobseeker does not recognize, especially if the emails include links to click on for more information or to proceed with the job application process.
  • Requests for detailed personal information, especially social security numbers or financial account details, before a job interview has even taken place.
  • Required credit checks to prove interest in a job, or to get an interview."

To read the whole article, see http://www.prweb.com/releases/job/scam/prweb2501944.htm.

Top Ten Most Dangerous Web Searches Risking Identity Theft

ABC news recently had an interesting article I just stumbled across regarding the "Top Ten Most Dangerous Web Searches", i.e. the web search terms most used by online hackers to install malicious code to steal your personal information and/or your identity.

According to the article "security firm McAfee, Inc. revealed how cybercriminals use popular search terms to unleash malicious software that can infect a computer and, in some cases, steal a user's identity. McAfee researchers analyzed more than 2,600 of the most popular search terms of 2008 from a range of sources, including the Google Zeitgeist and the Yahoo! 2008 Year in Review."

Some of the top ten most dangerous search terms are not that surprising, like "MySpace" (number 3) or "Free Music Downloads" (number 4) and "Free Music" (number 6). Others are a bit more intriguing, such as "Phelps, Weber-Gale, Jones and Lezak Wins 4x 100m Relay" (number 5) and "Word Unscrambler" (number 1).

The article also states that "'Search engines are our on-ramp, our highway and our off-ramp -- they're everything for Web travel," said Shane Keats, the research analyst with McAfee who led the study. 'The hacking community is very smart -- they can spot a trend as well as any trendspotter.' Just as pickpockets know they'll have the best odds of snatching a wallet on a busy city sidewalk, Internet thieves know they'll have the most luck by targeting crowds."

The article goes on to state "After analyzing the search terms, Keats and his team found that not only are hackers looking for crowds, they are also attacking Internet surfers who are ready to take an online action, like downloading a ringtone or logging in to a site with a name, address and social security number."

For the full article, see http://abcnews.go.com/Technology/AheadoftheCurve/story?id=7728160&page=1.

Oddly enough, in my nearly ten years representing identity theft victims as an attorney and my seven years experience before that as a law clerk/paralegal working on identity theft cases, I have never had a client come to me thinking that their identity was stolen over the internet. The culprit is most often a family member or close friend with access to the client's personal identifiers. Sad, but true.

June 02, 2009

President Obama must be reading my blog!

Remember the post I did about how to really get your free credit report. See http://fcralawyer.blogspot.com/2009/05/free-credit-reports-are-generally-not.html if you don't remember. Apparently, President Obama or someone in his administration read it. Ok, illusions of grandeur aside, I don't really think the President read my article. But they sure got the issue right in the credit card reform bill passed late last month.

As you all know (from reading my article perhaps), FreeCreditReport.com advertised through TV and radio commercials using a catchy jingle that led consumers to believe credit reports ordered on the site were actually free. Many people fell for the ruse, ordering their "free" credit report only to be forced to sign up for a $15 a month credit monitoring service to be able to get their "free" report.

The credit card reform law requires the Federal Trade Commission (FTC) to issue revised rules that require advertisers such as FreeCreditReport.com and others to acknowledge AnnualCreditReport.com as the only way to get a truly free credit report. Thanks to the new law, new FreeCreditReport.com commercials will include a statement that the credit report they provide for "free" is not the free credit report provided for by Federal law.

President Obama is carrying through with his promises to level the playing field for consumers, such as his excellent action of reversing the preemption being including in federal regulations. See http://fcralawyer.blogspot.com/2009/05/excellent-news-on-preemption-front.html and http://fcralawyer.blogspot.com/2009/05/more-on-president-obamas-preemption.html. That was big for consumers and the credit card bill is another great example of fair litigation for consumers. Once again, thank you President Obama, since I know you will read this. :)

June 01, 2009

15 U.S.C. 1681b - Part 1

We finally get to move past 15 U.S.C. 1681a on to 15 U.S.C. 1681b, which explains the permissible purposes for obtaining a consumer report. If its not permissible according to 1681b, then its impermissible and a violation of the Fair Credit Reporting Act.

"Permissible purposes of consumer reports

(a) In general. Subject to subsection (c), any consumer reporting agency may furnish a consumer report under the following circumstances and no other:

(1) In response to the order of a court have jurisdiction to issue such an order, or a subpoena issued in connection with proceedings before a Federal grand jury."

[There is some dispute as to whether a federal or state court subpoena is good enough for this section. In most states, subpoenas can be issued by a clerk, not just a judge. In the federal system, any attorney able to practice in any federal court can issue a subpoena. Experian refuses to produce a consumer report in response to just a subpoena but instead requires an actual order signed by a judge. Equifax and Trans Union, on the other hand, only require an issued subpoena.]

"(2) In accordance with the written instructions of the consumer to whom it relates."

[In other words, if the consumer consents in writing to the disclosure of his or her credit report.]

"(3) To a person which it has reason to believe

(A) intends to use the information in connection with a credit transaction involving the consumer on whom the information is to be furnished and involving the extension of credit to, or review or collection of an account of, the consumer; or"

[i.e. if the recipient of the consumer report is considering granting the consumer credit or is reviewing the consumer's existing account with the recipient or if the recipient of the consumer report is attempting to collect a debt from the consumer regarding whom the consumer report relates.]

"(B) intends to use the information for employment purposes; or"

[i.e. when a prospective employer uses a consumer report to make a decision described in 15 U.S.C 1681a(h) (i.e. employment, promotion, reassignment or retention)]

"(C) intends to use the information in connection with the underwriting of insurance involving the consumer; or"

[i.e. when an insurance company uses a consumer report to decide whether to insure a consumer or in setting a premium]

"(D) intends to use the information in connection with a determination of the consumer's eligibility for a license or other benefit granted by a governmental instrumentality required by law to consider an applicant's financial responsibility or status; or"

[I see this mostly with top secret type clearances where the government wants to make sure the consumer with the top secret clearance is not susceptible to bribes because of too much debt.]

"(E) intends to use the information, as a potential investor or servicer, or current insurer, in connection with a valuation of, or an assessment of the credit or prepayment risks associated with, an existing credit obligation; or"

[I am stumped by this one. If anyone can clue me in as to what this means, please do so.]

"(F) otherwise has a legitimate business need for the information

(i) in connection with a business transaction that is initiated by the consumer; or

(ii) to review an account to determine whether the consumer continues to meet the terms of the account."

[Pretty much just a catch all for anyone needing to review a consumer's credit report in connection with a transaction initiated by the consumer or to review an account the consumer already has.]

"(4) In response to a request by the head of a State or local child support enforcement agency (or a State or local government official authorized by the head of such an agency), if the person making the request certifies to the consumer reporting agency that

(A) the consumer report is needed for the purpose of establishing an individual's capacity to make child support payments or determining the appropriate level of such payments;

(B) the paternity of the consumer for the child to which the obligation relates has been established or acknowledged by the consumer in accordance with State laws under which the obligation arises (if required by those laws);

(C) the person has provided at least 10 days' prior notice to the consumer whose report is requested by certified or registered mail to the last known address of the consumer, that the report will be requested; and

(D) the consumer report will be kept confidential, will be used solely for a purpose described in subparagraph (A), and will not be used in connection with any other civil, administrative, or criminal proceeding, for any other purpose."

[The head of a child support enforcement agency can get a delinquent father's credit report but only if certain extra qualifications are met, including that paternity has been established, the consumer gets 10 days notice before the consumer report is pulled and the consumer report is kept confidential and not used for any purpose other than the collection of the past due child support.]

"(5) To an agency administering a State plan under Section 454 of the Social Security Act (42 U.S.C. 654) for use to set an initial or modified child support award."

[i.e. when a consumer report is used to determine how much child support should be awarded or modified to be.]

I'll continue in part 2 with subsection (b) of 15 U.S.C. 1681b.

A helpful site with lots of good information

Here's a nice site with lots of good information about your credit report and improving your credit score the right way - http://www.creditfairy.org/. Check it out.

No smiles allowed on some states' driver's licenses

Identity theft, as anyone who has been through it would know, is no smiling matter. One reason identity thieves are able to open some accounts is that they are able to get legitimate driver's licenses with their picture but someone else's name, Social Security number or other personal identifiers. I once represented an identity theft victim from Wisconsin whose identity thief used a fake Wisconsin ID to obtain a valid Tennessee driver's license with the identity thief's picture but my client's name and Social Security number on it.

Some of the 9-11 terrorists were even reported to be identity thieves, as they were able to use the personal identifiers (names, Social Security numbers, etc.) of others to obtain real driver's licenses. They then used their fraudulently obtained driver's licenses to obtain flying lessons.

The below article is about several states attempt to curb identity theft by taking away your right to smile on your driver's license, therby enhancing the ability of face recognition software to spot identity thieves.

Washington, May 31 (IANS) The licence to drive in the US no longer comes with a smile with several states asking people to wipe off that grin from their faces when posing for driver's licence photos.

Officials say the smile ban is for a good cause. The departments of motor vehicles (DMV) are simply trying to develop a facial recognition system that could compare customers' photographs over time to prevent fraud and identity theft.

The hitch is that people can't be smiling in their licence photos because the software won't match faces if the expressions differ.

'The technology works best when the images are similar,' said Virginia DMV spokesperson Pam Goheen, cited by the Washington Post. 'To prepare for the possibility of future security enhancements, we're asking customers to maintain a neutral expression.'

In Virginia that translates to a simple directive: 'Don't smile'. Arkansas, Indiana and Nevada allow slight smiles, but big grins are forbidden there too.

When asked how DMV employees are able to determine when customers might be smiling too much, Goheen explained that the process is automated. Naturally, the new software is programmed to reject attempts at exuberance or human warmth. 'It will send an error message if it detects a non-neutral expression,' she said.

Nationwide, 37 motor vehicle agencies use facial recognition technologies. The State Department also uses them for visa processing, and the Pennsylvania Justice Network compares crime scene photos and closed-circuit television footage with photos in a mugshot database of those previously arrested.

New York identity theft scheme busted!

Prosecutors in New York on May 27 indicted 18 people for operating a bank fraud and identity theft scheme that resulted in the cashing of more than 1,000 counterfeit checks at several large banks.

The 227-count indictment announced by Manhattan District Attorney Robert Morgenthau accused the defendants, most of whom live in the Bronx, of collecting customers' personal data with the help of bank employees they recruited for the operation, and using the data to manufacture thousands of fake checks.

Prosecutors said at least 17 banks were targeted, and at least 1,017 counterfeit checks were deposited in Manhattan branches. They said the probe revealed fraud at JPMorgan Chase & Co exceeding $1.446 million and "substantial fraud" at three other banks: HSBC Holdings Plc, Toronto-Dominion Bank and Wachovia, now part of Wells Fargo & Co.

Among the roughly 350 compromised accounts were those of New York City's police department, board of education, finance department, housing authority and transit authority, as well as corporate accounts of Bed Bath & Beyond Inc, designer Diane von Furstenberg, Cablevision Corp's Madison Square Garden and several hospitals, prosecutors said.

The alleged crimes took place between October 2007 and February 2009. Most of the defendants were charged with grand larceny, and all were charged with conspiracy and scheming to defraud, prosecutors said.

Another article about LifeLock

Here's another article about the California Federal Court's ruling that LifeLock must stop requesting fraud alerts for its customers. This article is from The Columbus Dispatch and indicates that the price of identity theft protection may rise.

FRAUD-ALERT LAWSUIT
Cost of ID theft protection could be about to rise
Monday, June 1, 2009 6:23 AM

SAN JOSE, Calif. - Companies that sell "identity theft protection" present an alluring but questionable proposition.

For as much as about $100 per year, the main thing they do is set fraud alerts that force banks to call people before new lines of credit are opened in their name. The alerts can be useful - but people can set them themselves, at no cost.

Now even that function could be taken away from the ID theft-prevention services.
A federal court in California has blocked Tempe, Ariz.-based Life-Lock, one of the industry's biggest players, from setting fraud alerts with Experian, one of the three main credit-reporting agencies that manage the fraud alerts.

Experian is suing LifeLock, claiming that LifeLock's automatic renewal of customers' fraud alerts - which happens every 90 days, when they expire - costs Experian millions of dollars in processing expenses.

In a ruling last week, a judge agreed with one of Experian's central arguments: that LifeLock isn't authorized to set alerts for consumers, and that federal law requires consumers to set alerts themselves by contacting credit bureaus directly.

The ruling has caused at least one ID theft prevention service, Debix, to announce that it plans to drop fraud alerts and offer credit-monitoring instead. The trend is likely to play out across the industry.

"It's going to be a game-changer," said Jay Foley, executive director of the Identity Theft Resource Center, a nonprofit organization based in San Diego.

For consumers, this means "identity theft protection" services could get more expensive - and less useful. Credit-monitoring services can cost $180 a year, and they don't always detect a fraud.

In contrast, fraud alerts are supposed to make it much harder for identity theft to be pulled off in the first place.

When a bank or retailer runs a credit check on someone for a new account, if a fraud alert pops up, the bank or retailer is required to call that person or use any other "reasonable policies and procedures" to verify their identity. That is meant to stop a scammer who goes into a retail store and tries, for example, to get instant credit under someone else's name and then walk out with a TV the other guy would be on the hook for.

LifeLock's chief executive, Todd Davis, who is known for plastering his Social Security number on billboards in an advertising gimmick, says his company will fight the court ruling and won't stop setting fraud alerts with the other two credit bureaus, Equifax and TransUnion.
Placing an alert at one bureau means an alert is placed at all three, because they have to notify one another.

"It's going to be business as usual until we hear they don't agree with the way we're interpreting this," Davis said. "We're not worried that this is some catastrophic decision."
At least one of his competitors disagrees.

Bo Holland, the founder of Debix, which offers ID theft protection for $24 a year, said his company will now stop setting fraud alerts and sell credit-monitoring instead. Holland said many of Debix's clients are corporations that subsidize the service for employees and customers after a breach.

Losing the ability to set fraud alerts is "definitely a step backward. It's been a very effective mechanism; creditors did a pretty good job of doing what they were supposed to do," he said. "Absolutely, I'm sad to see it go."

Holland noted, though, that fraud alerts have weaknesses, because banks will sometimes ask "security questions" of credit applicants instead of calling a consumer before opening a new account. If criminals have enough personal information about their victims, the con artists might be able to answer those questions, and the consumer would never get a call.

Representatives for another big ID theft protection service, TrustedID (which costs around $100 a year), did not return messages seeking comment.

Experian's lawsuit is not the first against LifeLock. Some customers have sued, saying they were misled about their level of protection.

The main thing that services such as LifeLock guard against is credit fraud. But there are other types of fraud, such as using someone's Social Security number to get a job or medical coverage, or giving it to police to impersonate someone who is innocent. A fraud alert on a credit report is powerless against those crimes.

LifeLock ordered to stop posting fraud alerts to consumers' Experian credit reports

LifeLock, who I posted about previously, has been ordered by a federal court in California to cease renewing fraud alerts for its customers with Experian, one of the big three credit reporting agencies.

In its lawsuit against LifeLock, Experian claims that LifeLock's automatic renewal of its customers' fraud alerts — which happens every 90 days, when the fraud alerts automatically expire — costs Experian millions of dollars in processing expenses. While I am not concerned about the cost to Experian, who profits millions every year by selling inaccurate information about consumers, I am concerned that LifeLock's practicing of requesting fraud alerts for customers who are not even claiming they are fraud victims is itself fraudulent. See my previous post about LifeLock at http://fcralawyer.blogspot.com/2009/05/lifelock-does-not-work.html.

U.S. District Judge Andrew Guilford, a federal judge in the Central District of California, agreed with Experian that the Fair Credit Reporting Act does not authorize LifeLock to set fraud alerts for consumers. Instead, Experian claimed and Judge Andrew Guilford ruled, the FCRA requires consumers to request fraud alerts themselves by contacting the credit bureaus directly. As a result, Judge Guilford granted Experian's motion for summary judgment, finding that LifeLock's requests for fraud alerts violated the Fair Credit Reporting Act. Judge Guilford's also ordered LifeLock to stop requesting fraud alerts on behalf of its customers.

In response to this ruling, at least one identity theft prevention service, Debix, announced it plans to drop fraud alerts and offer credit monitoring instead.

See the USA Today's full article about this ruling at http://www.usatoday.com/tech/news/2009-05-29-id-theft_N.htm?csp=27&RM_Exclude=Juno