Custom Search

September 30, 2011

Slow news day ...

... in the FCRA world.  But here are a few articles worth a quick look:

An article by Holly Culhane about concerns over Social Intelligence - a CRA that publishes reports to potential employers (and presumably others) utilizing "deep searches" of consumers' social networking sites such as FaceBook and MySpace. - http://www.bakersfield.com/news/business/economy/x2000241818/HOLLY-CULHANE-Beware-Internet-background-checks-have-risks

A Washington Post article about an FDIC probe of Discover Card's sales practices, including its marketing of its identity theft protection services - http://www.washingtonpost.com/business/industries/discover-faces-fdic-enforcement-after-probe-on-sales-practices-for-credit-id-theft-protection/2011/09/29/gIQAjEnc7K_story.html

A man sues his bar (CRAAAAZY, I know!) because they published his credit card's expiration date on multiple receipts over a period of time - this one's a stretch even for me.  Here's the article - http://www.baltimoresun.com/entertainment/music/midnight-sun-blog/bs-ae-koopers-lawsuit-0930-20110929,0,5085973.story

Enjoy!

September 29, 2011

Goldman Sachs got hacked

Hackers going by the twitter name of @CabinCr3w were apparantly able to hack Goldman Sachs' computer system.  The hackers sent off a tweet that directed followers of their twitter account to the Pastebin website.  The Pastebin website allows users to paste information to the website anonymously, where it is stored for a period of time.

The hackers pasted the personal information of Goldman Sachs CEO Lloyd Blankfein, including his age, recent addresses, education and even a listing of the legal cases he has been involved in.  The pasted information also included the e-mail addresses and titles of more than eighty employees of Goldman Sachs. 

Thousands at risk of identity theft from stolen laptop

A stolen laptop has put thousands of former patients of two Minnesota medical care providers at risk of identity theft.  A laptop containing the personal identifiers and other private information of approximately 14,000 patients of Fairview Health Services and 2,800 patients at North Memorial Medical Center, both of Minneapolis, was stolen out of a locked car located in the parking lot of a Minneapolis restaurant.

What's worse?  The data on the computer was not even encrypted.  In this electronic age, there's simply no excuse for massive amounts of personal identifiers not to be encrypted.

What's worse than that?  The medical care providers knew of the stolen laptop mere days after it was stolen on July 25 but are just now taking steps to inform the patients of the privacy breach.  Two months worth of proactive measures are now lost to these victims.

"Obviously, we take this event seriously," said Dr. Mark Werner, one of the senior physician leaders at Fairview. "It's deeply regrettable."

Obviously not.  Or you would have informed these patients whose identities your company exposed much, much sooner.  Just this week, two months too late, letters are being sent to those potentially affected, informing them of what happened and offering free services to protect them from identity theft.

The medical care providers claim "there's no evidence that the information has been misused."  Well, of course there's no evidence of any misuse.  You've kept the only people (other than the identity thieves) that would know of the misuse in the dark for the past two months.  Its very likely the identity thieves have already run amok using the credit histories of their victims and, if the victims are even aware of the theft of their identities, they have not linked the crime to the gross negligence of their medical care providers in failing to properly secure their personal identifiers. 

Give it a few more months (assuming those letters really do go out this week) and I bet there will be truckloads of "evidence of misuse". 

To those unfortunate victims of Fairview Health Services and North Memorial Medical Center, you need to check your credit reports, aggressively dispute any errors (whether resulting from identity theft or not) and then hire an attorney versed in the intricacies of the Fair Credit Reporting Act to represent you against the medical care providers who breached your trust and against any credit bureau or furnisher who refuses to correct your credit histories.  If you need the name of a good FCRA attorney in Minnesota, contact me and I will be happy to provide one.

September 28, 2011

Trans Union takes on Asset Acceptance

Trans Union has filed a lawsuit in the Circuit Court of Cook County, Illinois (i.e. Chicago - TU's home town) against Asset Acceptance, a collection agency notorious among us FCRA and FDCPA lawyers for reporting incorrect information and being pretty ruthless, immoral and unethical in its collection tactics.  For instance, I have sue Asset Acceptance many times.  I can think of one client who I have represent in not one, not two but three lawsuits against Asset Acceptance due to its illegal collection attempts against him.

Apparently, Trans Union's lawsuit against Asset Acceptance arises from a federal class action filed against Asset Acceptance alone.  This case is styled "Johnny Wang v. Asset Acceptance, LLC," Case No. C09-04797 SI in the U.S. District Court for the Northern District of California.  According to Trans Union, Asset Acceptance's reporting of incorrect information to Trans Union to be included in the credit reports it generates led to Trans Union being added as a co-defendant with Asset Acceptance in the class action.  This opened Trans Union up to some major financial exposure.

According to Trans Union's Complaint, which I have seen a copy of, at some point Asset Acceptance informed Trans Union that it "had some serious problems" with a file on 5.7 million consumers that it had previously reported to Trans Union for inclusion on Trans Union's credit reports regarding those 5.7 million consumers.  In particular, Asset Acceptance suspected that disputed accounts it had reported to Trans Union did not include the changes made as a result of the disputes.

Since Trans Union had already incorporated these accounts into its credit history database, it informed Asset Acceptance that it was removing all of Asset Acceptance's accounts from it database and that Asset Acceptance needed to re-report to Trans Union (correctly this time) all of its accounts.  But instead of providing corrected information, Asset Acceptance again provided incorrect information to Trans Union.

Trans Union was then added as a Defendant to the Johnny Wang federal class action, prompting Trans Union to sue Asset Acceptance for indemnification pursuant to its contract with Asset Acceptance that required Asset Acceptance to report correct information to Trans Union.

I'm not sure why Trans Union is surprised that Asset Acceptance is reporting incorrect information.  Like most junk debt buyers, Asset Acceptance has little if any proof to back up the debts it claims it is owed by consumers.  Yet, these bottom feeding junk debt buyers routinely "verify" to Trans Union and the other credit bureaus that the debts they report are indeed owed, even though they have no proof to back it their so called "verification".  If Trans Union really wanted the credit reports it generates regarding consumers to be more accurate, it would bar Asset Acceptance and the other junk debt buyers from including their accounts on Trans Union credit reports until such time as these companies actually present proof of the debts they claimed they are owed.  Until then, Trans Union's credit reports will continue to be chock full of inaccuracies.

Identity thieves go high tech

Do you think you are safe because you shred your credit card bills (after paying them of course), change your password often and don't respond to e-mails from banks where you've never been a customer?  Think again.  Identity thieves are now using a new high tech device to take advantage of new features on credit cards.  This new device, which costs less than $100, allows identity thieves to electronically pick your pocket without ever touching you.

Newer credit and debit cards, as well as some driver's licenses and passports, are being made with radio frequency identity chips that transmit information.  This relatively new feature has opened up an opportunity for identity thieves to use a small device to intercept the signals being transmitted by getting close to you, within 7 feet, from what I am told.  Thus, sporting events (like the Cubs/Cardinals game I went to over the weekend) are treasure troves, since at any time you are within 7 feet of multiple people. 

Many of the banks/credit card companies whose cards use these new identity chips offer protective sleeves for the credit cards.  But for those of us who already have a "George Costanza wallet" issue - see http://www.youtube.com/watch?v=yoPf98i8A0g if you don't understand the reference - this is not a good option.  Another option is a whole new type of billfold - a new type that is made of lighweight steel.  Never tried a wallet like that myself, but it is said to hamper the success of this type of identity theft.

As I have said before, there is no fool proof way to prevent identity theft.  Do your best, but be prepared to take action if and when it happens to you.  Dispute the fraudulently opened accounts early and often, with as much detail and supporting proof as you can.  And, when that doesn't work, hire someone like me to sue the credit bureaus and/or fraudulent credit grantors using the protections of the Fair Credit Reporting Act.  Only in a courtroom are your rights equal to the power of these corporations.

July 23, 2011

More about the social network credit bureau

I wrote previously about a new consumer reporting agency called the Social Intelligence Corporation that mines date from social networking websites such as Facebook and MySpace to build a consumer report about you.  My previous post is here - http://fcralawyer.blogspot.com/2011/06/social-intelligence-new-social-network.html

The latest article which provides a good bit of detail of how the Social Intelligence Corporation will operate is here - http://www.law.com/jsp/cc/PubArticleCC.jsp?id=1202501431464&How_Do_FTCApproved_Social_Media_Background_Checks_Work

July 20, 2011

Identity thief arrested at her own wedding

When the audience was asked whether anyone objected to this marriage, the police said "we do!".  A woman was arrested at her own wedding on a Michigan warrant for identity theft recently.  Police actually allowed Tammy Lee Hinton of Port Richey, Michigan to finish her wedding before hauling her off to jail.  She was held for less than half an hour before the new hubby bailed her out.  Wonder if he had some wedding cake on the way to the jail?

According to authorities Hinton used a computer to commit her crimes and charged around $3,000 in utility bills under her victim’s name in 2009. However when she learned there was a warrant for her arrest in Michigan, she fled to Florida.

Way to start off a marriage, huh?

Way to go Senator Gillibrand!

Talk about a no brainer.  U.S. Senator Kirsten Gillibrand from New York is pushing legislation that will force the removal of Social Security numbers from Medicare cards and communications from Medicare.


Forty million Americans carry Medicare cards with their Social Security number on them.  They also receive letters and other communications from Medicare that include their Social Security numbers.  As a result, these people are at an increased risk of identity theft if their cards or communications from Medicare are compromised.


“Listing Social Security numbers on Medicare cards needlessly leaves millions of New Yorkers susceptible to identity theft,” said Gillibrand. “We must protect Medicare beneficiaries by deterring identity theft. Removing Social Security numbers from Medicare cards is simple step to help keep our seniors personal information secure.”


The proposed legislation, aptly named the Social Security Number Protection Act, would eliminate the display of Social Security numbers on Medicare cards and would stop the Department of Health and Human Services from collecting Social Security numbers and from listing Social Security numbers in communications to Medicare beneficiaries.  


I think this legislation is long overdue and, based on what I've read (which does not include the text of the proposed legislation), is a no brainer.  Good to see someone in Washington proposing something useful.  Good job, Senator Gillibrand!

Credit Scores Disclosed for Free Starting Tomorrow ...

but only when you suffer an adverse action based on a credit report, such as when your credit application is denied.

Starting tomorrow, July 21, 2011, the latest amendments to the Fair Credit Reporting Act go into effect.  The new amendments require lenders or other users of credit scores to include those scores on their adverse action letters they send consumers who suffer the adverse actions.  The publication of the score will be in addition to the reasons for the adverse action and the identity of the consumer reporting agency whose report was used in the decision to deny credit already required to be part of the adverse action letter.

This is a helpful change to the law.  Before, consumers would only know what score was assigned to them during a credit application if litigation resulted and the lender's files were subpoenaed.  Scores purchased even thirty seconds later from the consumer reporting agency could bear little resemblance to the score used in the adverse action, since lenders often use their own credit scoring models, which differ from the credit scoring models used by the CRAs.  If you do buy a score, buy it directly from FICO, as that's the scoring model most lenders use.

July 19, 2011

Is your child a victim of ID theft?

Identity thieves are not ones to discriminate based on age.   In fact, some of their favorite targets are children.  This is so for various reasons, not the least of which is that their crime is likely to go undiscovered longer if the ID theft victim is a child.

A recent study performed by Debix, an identity theft monitoring company, found that 4000 children's identities had been stolen or otherwise compromised out of only 40,000 children surveyed.

So what do you do to protect your children's identity?  First, when your child turns 16, check his credit report.  This should leave enough time to correct any errors caused by any identity theft before the child starts college and starts needing credit in his own name.

Second, watch out for any early signs of identity theft.  If your minor son or daughter starts getting collection calls or preapproved credit offers, then you should request his credit reports from the Big Three to see what's up.

When you request the report, the credit bureaus should respond that there is no report regarding your child.  If they have a report, then your child is either the victim of identity theft or a mixed file.  How do you tell the difference?  Two ways - first, if all three bureaus have a file on your child, its probably identity theft.  If only one has a file, its likely a mixed file.  But, the only way to know for sure is to contact the creditors who appear on the report and find out what Social Security number was used to open the accounts.  If its your child's SSN, then he or she is a victim of identity theft.  If its a different but similar SSN, its a mixed file and all the blame lies with the credit bureau's faulty matching logic.

In either scenario, the first step after learning of the problem is to dispute the errors to the credit bureaus in writing.  If that doesn't work, after multiple tries, then you need to hire someone like me to sue the bureaus' for your child.  Remember, I'm only an e-mail away.

July 18, 2011

The Fourth Credit Bureau?

If you have been reading this blog much, you have probably seen me refer to Equifax, Experian and Trans Union as the Big Three.  They could also be called the Three Stooges, but I'd hate to insult Moe, Larry and Curly.

But what a lot of people don't realize is that there are many, many consumer reporting agencies outside of the Big Three.  I was reminded of this recently when I read a Washington Post article entitled "Five Facts about the Fourth Bureau".  At first I thought there might be a new bureau emerging (kind of like Shemp, the fourth stooge).  Instead, the article lumps together all the smaller, unorthodox consumer reporting agencies as the "fourth bureau".

The other bureaus tend to cover topics that are missed by the Big Three.  Some can be seen as niche market CRAs, such as the ones that collect information about rent paying history, which they then sell to potential landlords.  Other types of information collected by the "fourth bureau" are payment histories regarding utilities payments, cellphone bills, magazine subscriptions and gym memberships.  Some even keep up with whether consumers return their rental movies on time.  Others include companies that compile investigative consumer reports and that provide criminal history type reports that can be used for background checks.

These smaller bureaus can play important roles as over 30 million U.S. consumers don't show up in the Big Three's databases.  These consumers are in a credit morass, as they can not get a loan without a credit history and can not get a credit history without getting loans.  But they can rent apartments, rent movies, sign up for utilities, etc.  The payment histories generated by these actions can sometimes be used in place of a more traditional credit report.

But these types of payment histories can also hurt a consumer's chances of getting credit if they do not reflect a responsible payment pattern, or if they contain damaging errors, which they are apt to contain.  Approximately 25% or more of the Big Three's reports contain damaging errors, so the other bureaus are likely to have a similar error rate.  The good news ... even though these companies are not the "Big Three", they are still subject to the vast majority of the requirements of the Fair Credit Reporting Act, including the requirement that they provide to consumers upon request a complete report of all information in their database about the consumer and 15 U.S.C. 1681i's requirement that they reasonably investigate consumer's disputes of inaccurate information.

The down side ... to get your report from the small bureaus will cost you some money (approximately $11) since the yearly free credit report requirement only applies to the Big Three.  Consumers can also get a free credit report from any CRA if they are denied credit (or suffer some other adverse action) as a result of the contents of the CRA's report.

The same rules regarding disputing errors also apply to the "fourth bureau" ... namely disputing in writing and dispute often.  If that doesn't work, hire someone like me to sue for damages resulting from the errors (which usually also includes the benefit of a corrected credit report.  Funny how a lawsuit will do things that a multitude of even the best dispute letters can not.)  If any of  you need help with the Big Three or the "fourth bureau", I'm only an e-mail away.

July 17, 2011

Starbucks' new iPhone app a risk for identity theft?

According to 9News.com (Colorado's News Leader), Starbucks' new iPhone app, that allows iPhone users to pay for purchases, check gift card balances and purchase gift cards for others, is causing identity theft concerns.

Actually, the identity theft concerns are not really related to Starbucks' app as the concerns would apply to many apps.  Any app that encourages the storage of personal financial information (i.e. credit card info, passwords, etc.) on a mobile device increases the chances of identity theft, just because mobile phones are easier to lose than a desktop computer.  Just ask my niece, who loses her cell phone at what seems like a rate of one a month.  But that's a subject for another blog.

One of the next waves of technology will no doubt be some way to pay for purchases using your cell phone rather than a credit card.  But the trade off for something so convenient is the increased risk of identity theft.  Just like the trade off of being able to receive instant credit decisions while you wait to buy a toaster at Sears is that the decision must be based on information that can be transmitted to Sears while you wait.

True story - I once had a client who was unable to purchase a toaster on credit at a Sears because of an error on his credit report.  The defendant in the case was Experian, one of the three national credit bureaus.  Their argument regarding the credit denial was that he was not denied credit due to the error but due to the statement added to his credit report regarding the error, indicating that he was an identity theft victim and that he should be called at his home number to verify his identity before being granted credit.  In the case of instant credit, he would never be home to receive the verification call, since he would be out shopping, waiting for the credit decision.  Kind of a catch 22, huh?  Client should have used his cell phone number but, then again, this was back before everyone had cell phones.

Anyway, the trade off for "instant" stuff is almost always going to be an increased risk of something such as identity theft.  The trick is first recognizing the increased risk and then building safeguards into the app to handle the increased risk.  Hopefully, the apps of Starbucks and others take this into account when designing their apps.

June 28, 2011

Identity theft - the latest summer risk for kids?

Its summer.  I know this due to the repeated "I'm bored" comments I hear from my nine year old.

Summer also brings additional risk of identity theft to children.  Thanks to the additional free time caused by the long days of summer, children spend more time in front of the computer or on their internet capable cell phones.  With this additional time online comes the additional risk of identity theft.

Why would an identity thief want to steal the identity of a child?  Basically because the child's credit history is a blank slate and can be misused longer than an adult's credit history, since the kid is not out doing the things that cause identity theft victims to learn of the theft of their identity, like applying for credit.

“The younger the victim, the more time these thieves have to exploit the child’s identity,” said Sandy Chalmers, Administrator of the Wisconsin Division of Trade and Consumer Protection. “Identity theft against a child can go undetected for years and do a lot of damage to their good name.”


So, parents, please warn your kids not to give out personal information online unless and only if its to a reliable source.  And, be sure to monitor what your kids are doing online.  A little bit of prevention can prevent a lot of problems later on.