ChoicePoint ID Theft Victims' Day Has Come
Roy Mark writes on internetnews.com:
Victims of the ChoicePoint identity theft scandal will soon be receiving claims forms to recover out-of-pocket expenses.
The Federal Trade Commission (FTC) mailed more than 1,400 of the forms Wednesday and made them available for download at the FTC ChoicePoint site. Restitution claims must be postmarked by Feb. 4.
The victims will be paid out of a $5 million fund established by ChoicePoint as part of its January settlement with the FTC. ChoicePoint also agreed to pay a $10 million fine for failing to adequately protect the consumer information in its databases.
The Georgia-based ChoicePoint is a credit report service used by more than 50,000 landlords and merchants to conduct background checks on potential tenants and customers. It also has several law enforcement and government agencies as clients.
More
here.
IRS Hires ChoicePoint To Leak Your Info
Ay caramba.
I can think of no other way to sum it as nicely as Mike, over at techdirt.com, already has:
Contributed by Mike on Thursday, June 30th, 2005 @ 01:08AM
from the bad-timing dept.
ChoicePoint is the personal data company that kicked off this sudden focus on data leaks by cheerfully handing over thousands of records to a bunch of crooks who had no business with the data. So, now that our government is planning to put in place stricter laws punishing such activity, how do they reward ChoicePoint? Politech notes that the IRS has handed over a huge contract to ChoicePoint. That'll show them. Of course, perhaps even more worrisome is the fact that the IRS will now be using this info to checkup on tax payers, when reviews of ChoicePoint's data has shown repeatedly that its data is often wrong -- with many people seeing criminal records when they've never been in trouble. Also, it's worth pointing out that ChoicePoint is a spinoff from Equifax, the company whose CEO tap danced around whether or not they've leaked any data and claimed that letting you see what data they had on you was unconstitutional and un-American. Doesn't that make you feel safer?
ChoicePoint to Pay Fine for Second Data Breach
Grant Gross writes on PC World:
Data broker ChoicePoint, the victim of a 2004 data breach affecting more than 160,000 U.S. residents, has agreed to strengthen its data security efforts and pay a fine for a second breach in 2008, the U.S. Federal Trade Commission said Monday.
ChoicePoint, now a subsidiary of Reed Elsevier, will pay US$275,000 to resolve the newest FTC complaint. The FTC accused the company of failing to implement a comprehensive information security program to protect consumers' personal information, as required by the agency after the 2004 breach.
The April 2008 breach compromised the personal data of 13,750 people, the FTC said in a press release. ChoicePoint turned off a "key" electronic security tool used to monitor access to one of its databases, and failed to detect that the security tool was turned off for four months, the FTC said.
For a 30-day period, an unknown hacker conducted thousands of unauthorized searches of a ChoicePoint database containing sensitive consumer information, including Social Security numbers, the FTC said. After discovering the breach, the company notified the FTC.
If the software tool had been working, ChoicePoint likely would have detected the intrusions "much earlier," the FTC said.
More
here.
Cybercrime Book Excerpt: Zero Day Threat
Byron Acohido and Jon Swartz write on Wired.com:
When a shadowy Nigerian national with the nickname Mr. O finagled his way into the vast files of data broker ChoicePoint in 2003, he struck a mother lode of confidential information -- by internal ChoicePoint estimates, records of up to 4.3 million individuals.
By the time ChoicePoint publicly disclosed what was then the largest data-security breach, the FBI and Los Angeles police were investigating, lawmakers demanded hearings, and ChoicePoint vowed to remake itself. Some privacy advocates insisted the incident would underscore the dangers of data theft and ID fraud.
And yet, data breaches got bigger and broader in the intervening years, as Internet-based commerce and social networking inexorably expand. Since ChoicePoint, online scammers have repeatedly victimized corporations and their customers. The most audacious was the theft of records of as many as 94 million credit card transactions from giant retailer TJX, parent of 2,500 TJ Maxx and Marshall's stores.
Amid the wholesale rip-off of consumer data through cybercrime, USA Today reporters Byron Acohido and Jon Swartz began investigating the evolution of hacking from harmful pranks to a $100 billion-per-year criminal enterprise worldwide. Their resulting book, Zero Day Threat, examines the con men and cybercrooks who are exploiting security holes in online banking and shopping services.
Much more
here.
Who's Guarding Your Data in the Cybervault?
Jon Swartz and Byron Acohido write in USA Today:
In a remarkable turnaround, ChoicePoint, the giant data broker excoriated two years ago for its lack of precautions as it went about gathering and selling personal data, has recast itself as a model corporate citizen.
California's milestone data-theft disclosure law forced ChoicePoint in February 2005 to reveal that it had sold sensitive information for at least 166,000 people to a Nigerian con artist posing as a debt collector. The Federal Trade Commission hit ChoicePoint with a record $10 million fine and ordered it to set aside $5 million to aid data breach victims.
The once-obscure data broker, tucked away in a nondescript business park 20 miles north of Atlanta, also embraced extensive reforms. The result: ChoicePoint is regarded by a dozen leading privacy advocates interviewed by USA TODAY as the most responsible company among dozens in the lightly regulated, fast-growing field of aggregating and selling sensitive information.
More
here.
ChoicePoint: Keeping Your Enemies Close?
Gary Rivlin writes in The New York Times:
In January, the Federal Trade Commission hit ChoicePoint with a $10 million fine, the largest civil penalty in the agency’s history, for security and record-handling procedures that violated the rights of consumers. Under the settlement, it also required ChoicePoint to set aside an additional $5 million to help those suffering financial harm because of its failure to provide adequate safeguards against data breaches.
But the financial penalties were nothing compared to the rehabilitation project confronting this hitherto invisible player in the global marketplace.
For years, ChoicePoint’s top management had assured the world that it carefully protected its databases from intruders: Our systems are bulletproof. Intruder-proof. Believe us.
But then, in February 2005, the company had to acknowledge that it had focused so intently on preventing hackers from gaining access to its computers through digital back doors that it had simply overlooked real-world con artists strolling unnoticed through the front door.
More
here.
FBI Signs 5-Year Contract with ChoicePoint for Analysis Software
William P. Dizard III writes on GCN.com:
The FBI has expanded its use of software that helps analyze how criminal organizations operate by signing a five-year licensing agreement with ChoicePoint Inc. of Alpharetta, Ga., the company announced today. ChoicePoint, which will provide products from its subsidiary i2 Inc., estimated the value of the contract at $12 million.
ChoicePoint, a major data aggregator that culls information from dozens of public databases and distributes it to corporations and government agencies, links its information with i2’s Analyst’s Notebook tool and other software.
More
here.
FTC Fines ChoicePoint Over Data Breach
An AP newswire article by Harry S. Weber, via SFGate.com, reports that:
The Federal Trade Commission said Thursday that data warehouser ChoicePoint Inc. will pay $15 million to settle charges that its security and record-handling procedures violated consumers' privacy rights and federal laws.
The FTC said it had fined the Alpharetta, Ga.-based company $10 million and that Choicepoint would pay an additional $5 million that will be used to compensate consumers.
Choicepoint had revealed last year that its massive database of consumer information was accessed by thieves.
ChoicePoint notifies another 17,000 consumers on possible breach
An AP newswire article, via The Mercury News, reports that:
ChoicePoint Inc., the company that disclosed earlier this year that thieves had accessed its massive database of consumer information, said Tuesday in a regulatory filing it has sent out another 17,000 notices to people telling them they may be victims of fraud.
The Alpharetta-based company had said in February, after announcing the breach, that it had notified roughly 145,000 consumers that they may have had their personal information improperly accessed.
That number has now increased to 162,000, ChoicePoint said in its quarterly report to the Securities and Exchange Commission. The filing did not detail reasons for the increase, though the company had previously said the number could ultimately be higher.
ChoicePoint said Tuesday its review of the data breach is ongoing and there could be further notices sent out.
Update: Miami-Dade police officer suspended in unauthorized data access
An AP newswire article, via The Mercury News (obnoxious, but free, registration required -- or try using BugMeNot.com), reports that:
A Miami-Dade police officer has been relieved of duty and is under investigation for allegedly obtaining unauthorized access to Social Security numbers and other personal data on as many as 4,689 people maintained by ChoicePoint Inc.
The company, based in Alpharetta, Ga., said Friday that the U.S. Secret Service was investigating the matter but that it was unclear whether any identity theft had occurred.
The employee, ChoicePoint said in a letter to the potentially affected consumers, was not authorized to use the Miami-Dade Police Department's account with the company and ``had accessed information illegally and acted outside the scope of his employment.''
The consumer information accessed, with log-in and password, included Social Security data, drivers license numbers and dates of birth.
Detective Mary Walters, a Miami-Dade police spokewoman, said the officer involved was relieved of duty and an internal investigation was under way.
She declined to provide the officer's name or any details about where in the department the officer worked.
Update: Bob Sullivan
writes on
MSNBC, that in addition to the Miami-Dade incident:
The three other incidents announced Friday were:
- Two California-based private investigators, Kenneth Beck and Robert Starr, allegedly used ChoicePoint’s data to hunt for possible identity theft victims, Lee said.
- A Texas-based firm named RPM was found to have improperly accessed data.
- An employee of an "accredited insurance” company that ChoicePoint would not name, citing contracts with the firm, was also alleged to have improperly accessed records.
In total, the three incidents resulted in 547 warning notices being sent to victims, Lee said.
Chief ChoicePoint screener says no employees involved in breach
An AP newswire article, via The Mercury News, reports that:
ChoicePoint Inc.'s chief screener said Monday no employees were involved in a breach last fall of the company's massive database of personal information, and she stressed that while procedures need to be improved, she doesn't believe any individuals made mistakes.
Carol A. DiBattiste, the former deputy administrator of the Transportation Security Administration who took over as ChoicePoint's head credentialing, compliance and privacy officer in May, told The Associated Press that while she hasn't been involved in the company's investigation of the breach, other executives have told her no employee contributed to what happened.
"What I can tell you, it did not involve a ChoicePoint employee,'' DiBattiste said in her first interview since assuming her new job.
ChoicePoint Subsidiary Rolls Out License Plate Tracking System in UK
Luke O'Brien writes on Threat Level:
Giant American data peddler ChoicePoint last week unveiled a new system in the United Kingdom for analyzing the thousands of license plate numbers collected by automated cameras nestled surreptitiously throughout the English heather.
Called the "analyst's workstation" and designed by i2, a ChoicePoint-owned company, the system interfaces with three major databases and uses license plate information to help cops bust bad guys.
More
here.
Reed Elsevier Seeks to Acquire ChoicePoint for $4.1B
Ellen Nakashima writes in The Washington Post:
Reed Elsevier PLC, the owner of the LexisNexis Group, is seeking to acquire ChoicePoint Inc. in a $4.1 billion cash deal that would create a global data brokering service.
By combining database giants LexisNexis and ChoicePoint, Reed Elsevier would handle information about hundreds of millions of people and sophisticated software to handle it. Both companies play key roles in law enforcement, homeland security and intelligence, as well as providing information to the private sector.
Both also have been hit by identity theft and security problems.
More
here.
FTC Looks for More Victims of ChoicePoint Breach
Grant Gross writes on InfoWorld:
The U.S. Federal Trade Commission (FTC) is looking for victims of a data breach at ChoicePoint announced in early 2005.
Victims with out-of-pocket expenses due to the breach have until Aug. 18 to file claims and be eligible for payments from a $5 million fund that ChoicePoint agreed to pay in its January 2006 settlement with the FTC.
The FTC has now mailed reimbursement claim forms to 2,400 consumers who may have been victims of identity theft due to the breach, the agency said in a speech. The FTC has mailed claim forms to 1,000 consumers since December 2006, it said.
In addition, the FTC has created a Web site where consumers who do not receive a claim letter can download a claim form and get more information about the claims process.
More
here.
ChoicePoint overhaul completed, company says
Joris Evers writes in in C|Net News:
ChoicePoint, the data broker that leaked information on about 145,000 Americans, says it has completed changes to its business to prevent such a breach from happening again.
"In fact, we've gone beyond our announced commitments to make substantial changes in the past 90 days," ChoicePoint spokesman Dan McGinn said in an e-mail late Tuesday.
The Alpharetta, Ga.-based data broker is clarifying its position after a spokeswoman told News.com on Friday that the transition process was ongoing and that it would be some time before the company could announce its completion.
Accuracy of Commercial Data Brokers
Thanks to Bruce Schneier for bringing our attention to this study. Bruce writes in his blog, Schneier on Security:
PrivacyActivism has released a study of ChoicePoint and Acxiom, two of the U.S.'s largest data brokers. The study looks at accuracy of information and responsiveness to requests for reports.
It doesn't look good.
From the press release:
100% of the eleven participants in the study discovered errors in background check reports provided by ChoicePoint. The majority of participants found errors in even the most basic biographical information: name, social security number, address and phone number (in 67% of Acxiom reports, 73% of ChoicePoint reports). Moreover, over 40% of participants did not receive their reports from Acxiom -- and the ones who did had to wait an average of three months from the time they requested their information until they received it.
I spoke with Deborah Pierce, the Executive Director of PrivacyActivism. She made a couple of interesting points.
First, it was very difficult for them to find a legal way to do this study. There are no mechanisms for any kind of oversight of the industry. They had to find companies who were doing background checks on employees anyway, and who felt that participating in this study with PrivacyActivism was important. Then those companies asked their employees if they wanted to anonymously participate in the study.
Second, they were surprised at just how bad the data is. The most shocking error was that two people out of eleven were listed as corporate directors of companies that they had never heard of. This can't possibly be statistically meaningful, but it is certainly scary.
ChoicePoint: The Private Spy Among Us
Shane Harris:
To help the government track suspected terrorists and spies who may be visiting or residing in this country, the FBI and the Defense Department for the past three years have been paying a Georgia-based company for access to its vast databases that contain billions of personal records about nearly every person -- citizens and noncitizens alike -- in the United States.
According to federal documents obtained by National Journal and Government Executive, among the services that ChoicePoint provides to the government is access to a previously undisclosed, and vaguely described, "exclusive" data-searching system. This system in effect gives law enforcement and intelligence agents the ability to use the private data broker to do something that they legally can't -- keep tabs on nearly every American citizen and foreigner in the United States.
More
here.
FTC Hasn't Paid Victims of Breach at ChoicePoint
An AP newswire article, via The Boston Globe, reports that:
Nearly eight months after regulators trumpeted a settlement with ChoicePoint Inc. over a data breach, the government has not paid any money to victims from a $5 million fund that was to be set up as part of the agreement.
The Federal Trade Commission also has not yet implemented procedures for how the 800 fraud victims it has identified so far can be compensated from the fund, nor has it hired anyone to administer it , said FTC spokeswoman Claudia Bourne Farrell.
More
here.
ChoicePoint Makes Fraud Detection Buy
Clint Boulton writes on internetnews.com that:
ChoicePoint, which had the personal information of 145,000 people pried from its grasp recently, has improved its ability to help financial service and insurance customers detect fraudulent activity.
The company, one of the largest data warehouses in the U.S., with Social Security numbers and credit reports on almost every American, said it acquired fraud-detection software maker Magnify, Inc.
Terms of the deal were not made public.
ChoicePoint Division Changes Tack
Article via Wired News: "A division of ChoicePoint that conducts background checks for employers and other organizations will begin notifying individuals when it provides damaging personal information about them. The newly announced policy is designed to bring the company into compliance with a federal law that requires such notice in certain cases."