Showing posts with label choicepoint. Show all posts
Showing posts with label choicepoint. Show all posts

Monday, June 11, 2007

Choicepoint almost regains pre-breach value

Though this article from Yahoo! Business is not about the privacy problems that plagued ChoicePoint and that made the company the poster boy for privacy breaches, I found it interesting to take a look at the chart of the company's stock value. In the last twelve months, the company's share value has slowly increased to barely recover the value lost by the high-profile breach. The total value lost between then and now is staggering.

See: Out of the Gate: ChoicePoint Jumps: Financial News - Yahoo! Finance.

Friday, June 01, 2007

ChoicePoint Settles Data Security Case

Choicepoint, the poster child of security breaches, reportedly has settled with the Attorneys General of 44 states. The settlement is nominal cash-wise ($500,000) and includes requirements for tougher security measures:

ChoicePoint Settles Data Security Case - New York Times

June 1, 2007

ChoicePoint Settles Data Security Case

By REUTERS

ChoicePoint has settled with 44 states over a data breach that potentially gave criminals access to personal information from more than 145,000 consumers.

The company agreed to adopt stronger security measures and pay $500,000 to the states, Richard Blumenthal, the attorney general of Connecticut, said yesterday.

ChoicePoint, which sells information about consumers to employers, marketers and others, said in 2005 that criminals posing as legitimate businesses had gained access to consumer data, including Social Security numbers and credit histories.

The company, based in Alpharetta, Ga., was one of several to announce large-scale security breaches in 2005, raising identity theft as an issue for many legislators and regulators.

ChoicePoint characterized the settlement as “fair and reasonable.”

In January 2006, ChoicePoint settled a case with the Federal Trade Commission involving the security breach.

Monday, December 11, 2006

FTC to begin compensating ChoicePoint breach

The US Federal Trade Commission has finally begun the process to compensate victims of ChoicePoint's enormous data breach. Only those who ultimately were victims of fraud are being compensated, excluding those whose data was merely leaked:

FTC to Reimburse ChoicePoint Victims: Financial News - Yahoo! Finance:

FTC Mails Claim Forms to 1,400 ChoicePoint Victims

WASHINGTON (AP) -- Victims of identify theft stemming from a security lapse last year at consumer data provider ChoicePoint Inc. can seek reimbursement from a $5 million fund set up to recoup their losses, the Federal Trade Commission said Wednesday.

Alpharetta, Ga.-based ChoicePoint collects, sells access to and analyzes information on consumers. The company agreed Jan. 26 to pay the FTC $15 million to settle charges that the company's security and record-handling procedures violated consumers' privacy rights when thieves infiltrated the company's massive database.

Identity thieves gained access to ChoicePoint's database by posing as small business customers, possibly compromising the personal information of 163,000 Americans, according to the FTC.

The settlement included a $10 million fine -- the agency's largest ever -- and $5 million for a victims' fund that will be used to reimburse those who file claims.

Friday, November 17, 2006

The rehabilitation of ChoicePoint

Last Saturday's New York Times ran a lengthy article on the rehabilitation of ChoicePoint. The one-time poster child for privacy fiascos has since apparently cleaned up its act. Now members of the "privacy possee" are quoted as singing the company's praises after it gots its house in order. Right after the high-profile privacy breach, representatives of the company contacted members of the privacy community (I even got a call) to ask what they did right and what they did wrong in responding to the incident. Since then, many of their harshest critics hail the company as a model for the data brokerage industry. Check it out: Keeping Your Enemies Close - New York Times.

The article also has a great timeline illustrating the number and magnitude of privacy incidents in the US over the past few years:

Wednesday, September 20, 2006

ChoicePoint victims uncompensated despite $5M fund

The Associated Press is reporting that months after a $5 million settlement assembled a pool of funds to compensate people for the ChoicePoint breach, nobody has seen a penny. "It's under review." See: AP: FTC yet to pay ChoicePoint victims - Yahoo! News.

Wednesday, August 23, 2006

Privacy hall of shame

Wired News has released a top ten list for its suggested entries in the "Privacy Debacle Hall of Fame". The countdown is:
Wired News: Privacy Debacle Hall of Fame

10. ChoicePoint data spill
9. VA laptop theft
8. CardSystems hacked
7. Discovery of data on used hard drives for sale
6. Philip Agee's revenge
5. Amy Boyer's murder
4. Testing CAPPS II
3. COINTELPRO
2. AT&T lets the NSA listen to all phone calls
1. The creation of the Social Security Number

The Wired article has more details on each of the above blunders.

Via Concurring Opinions and Rob Hyndman.

Friday, April 28, 2006

It's the cover-up, stupid

In the hundreds of security and privacy breaches reported in the last few years, the companies involved that have fared the best are those that have been forthcoming with information and appear to be genuinely interested in the well being of the people involved. (I say "appear to be" because it doesn't really have to be sincere, but it has to benefit the individual. Once you can fake sincerity, you've got it made.) Those that have fared the worst are those that lied, misled customers, otherwise tried to cover it up or trivialize the breach.

Accidents happen and any company that has customer data on hand is at risk, to some degree or another. No security system is perfect. The biggest consequence of a breach is probably not an award of damages from the court but the loss of trust of customers and other stakeholders. The senior director at Lexis Nexis is quoted in a recent Network World article (Disclosure meant less pain in data theft) as confirming this:

But when the damage became clear, LexisNexis made an immediate decision to be forthcoming and transparent about the breach, he said. "We tried to do the best job we could," he said.

The company contacted all those who were affected by the attack using the framework of a California data security disclosure law passed in 2003 as a guide, Cronin said.

The law is catching up after the high-profile cases of last year, including ChoicePoint, a data broker that acknowledged divulging sensitive personal information to identity thieves posing as customers. So far in the U.S., 20 states have implemented notification laws, and a federal law is under consideration.

After the data breach, LexisNexis took several steps to implement stronger security, Cronin said. The company reviewed the security of all its Web applications and created new procedures for verifying customers with access to sensitive data, he said.

LexisNexis encouraged certain customers to sign up for anti-virus software. It revamped online security access, looking at password complexity and expiration times. The company also implemented measures to automatically detect anomalies in use of its products to identity potential security problems, Cronin said.

LexisNexis learned other lessons. Passwords are dead, Cronin said, and two-factor authentication is recommended. But front-door perimeter attacks are less likely than the persistent weak link: people.

Now ask yourself why ChoicePoint is synonymous with "privacy breach" and not Lexis Nexis.

Tuesday, April 11, 2006

ChoicePoint Announces New PATRIOT Act Compliance and OFAC Compliance Software

About 99% of this is marketing speak, but parts of this press release from ChoicePoint look interesting:

ChoicePoint Announces New PATRIOT Act Compliance and OFAC Compliance Software:

New Bridger Insight XG™ to Streamline Customer Screening

ALPHARETTA, GA (PRWEB) April 4, 2006 -- ChoicePoint today announced the official launch of Bridger Insight XG, a new Office of Foreign Asset Control (OFAC) and USA PATRIOT Act (PATRIOT Act) compliance solution. The new solution is now available to more than 4,000 existing Bridger Insight clients and other businesses across the banking and finance, insurance, securities, mortgage, automotive, gaming and public sectors.

Bridger Insight XG will reduce manual workload and streamline PATRIOT Act compliance and OFAC compliance workflow across an organization using new technologies designed to greatly simplify customer screening (including OFAC checks and ID verification) and due diligence processes. The new product is designed to help businesses more efficiently identify suspected terrorists and prevent crimes such as money laundering and ID theft.

Through new automated compliance workflow and case management tools, this new OFAC and PATRIOT Act compliance software can help users realize significant cost savings and greatly reduce false positive hits. Turn-key enterprise-wide deployment is another feature of the new software, which is equipped with the latest security and expanded audit capabilities.

Bringing extensive experience as a pioneer of OFAC compliance and PATRIOT Act compliance software, Bridger Insight XG helps clients make informed decisions, while saving time and reducing workload costs.

Bridger Insight solutions are used every day by the majority of the top 25 U.S. banks and thousands other businesses across the financial, insurance, securities, mortgage, automotive, gaming and public sectors to perform real-time and scheduled batch customer screening, utilizing more than 24 up-to-date watch lists, with access to extensive business and individual identity information, Factiva® Media and in-depth politically exposed persons databases.

More information about Bridger Insight XG can be obtained at www.BridgerInsight.com/XG.

Anyone know what a "in-depth politically exposed persons database" is? If so, leave a comment. Sounds interesting...

Sunday, February 26, 2006

Notification is the new moral imperative

Adam Shostack often has interesting things to say about privacy. He's posted, at Emergent Chaos, about the recent incident involving the University of Texas and their voluntary notice for the loss of encrypted patient information. Here Adam's take on their response:

Emergent Chaos: Analysis of University of Texas, 4,000 encrypted SSNs, Laptop:

Since Choicepoint, there's been a dramatic shift in the way these incidents are perceived. Assertions of caring about privacy have transformed into a moral duty to report, even when the law doesn't require it. Work to undercut the 21 state laws in place by groups like the American Bankers Association misses the point. When there's a breach of personal data, the risk is on the citizen or consumer, not on the organization that lost control of the data. The organization has demonstrated that their risk management decisions don't have the results that customers want. That means the risk analysis must be done by the person, not the organization. For the person to do the risk analysis, they need to know what's happened.

We like transparency. We accept apologies (when they're not tortured or convoluted). We prefer to work with organizations that don't keep us in the dark, `for our own good.' Finally, we don't trust anyone who has lost control of data to get the next analysis right. Whatever bad laws happen to come out of Congress, there's a new social consensus, and the University did exactly the right thing.

Technorati tags: :: :: :: :: :: .

Saturday, February 25, 2006

Cardsystems settles with the FTC

The US Federal Trade Commission has settled its complaint against CardSystems after a breach at the company comproised the personal information for forty million credit and debit card users. The company had, against its agreement with the card-issuers, kept information related to transactions it was processing and failed to secure it adequately.

Somewhat oddly, the LA Times article says that the FTC could not levy any civil damages or penalties, as it did with ChoicePoint, without mentioning why.

CardSystems Settles Charges

From Associated Press

February 24 2006

WASHINGTON — A data breach that left 40 million customer accounts vulnerable to hackers will lead to tighter security measures to protect millions of credit and debit card users, Federal Trade Commission officials said Thursday.

CardSystems Solutions Inc. has settled charges that the company broke the law by failing to ensure adequate safeguards for sensitive customer information. The breach resulted in millions of dollars in fraudulent purchases, the commission said.

The settlement calls for better safeguards to protect consumer data.

The FTC could not seek civil penalties under the law it accused CardSystems of violating.

Atlanta-based CardSystems processed credit card and other payments for banks and merchants. Last summer, it was disclosed that tens of millions of mostly MasterCard and Visa accounts were exposed to possible fraud after a hacker broke into the company's computer system.

"CardSystems kept information it had no reason to keep and then stored it in a way that put consumers' financial information at risk," FTC Chairwoman Deborah Platt Majoras said.

CardSystems' assets have since been bought by San Francisco-based Pay by Touch. The settlement requires Pay by Touch to implement a comprehensive security program and obtain independent audits every other year for 20 years.

Technorati tags: :: :: .

Thursday, January 26, 2006

Record, punitive fine for Choicepoint's data disaster

The FTC has imposed a record-breaking $10 million dollar penalty on ChoicePoint after the very high-profile incident that saw criminals obtain the personal information of 163,000 Americans. The FTC also ordered that the company pay an additional $5 million to compensate affected individuals.

This one incident has cost the company untold millions. They have paid lawyers, consultants, paid for credit monitoring for each affected individual, paid to deal with the investigation, paid to deal with the media, their share value has tanked and is only just recovering. I don't really think there is a better example for the proposition that bad security and bad privacy are bad for business.

Check out the FTC press release:

Choicepoint Settles Data Security Breach Charges; to Pay $10 Million in Civil Penalties, $5 Million for Consumer Redress:

For Release: January 26, 2006

Choicepoint Settles Data Security Breach Charges; to Pay $10 Million in Civil Penalties, $5 Million for Consumer Redress

At Least 800 Cases of Identity Theft Arose From Company’s Data Breach

Consumer data broker ChoicePoint, Inc., which last year acknowledged that the personal financial records of more than 163,000 consumers in its database had been compromised, will pay $10 million in civil penalties and $5 million in consumer redress to settle Federal Trade Commission charges that its security and record-handling procedures violated consumers’ privacy rights and federal laws. The settlement requires ChoicePoint to implement new procedures to ensure that it provides consumer reports only to legitimate businesses for lawful purposes, to establish and maintain a comprehensive information security program, and to obtain audits by an independent third-party security professional every other year until 2026.

“The message to ChoicePoint and others should be clear: Consumers’ private data must be protected from thieves,” said Deborah Platt Majoras, Chairman of the FTC. “Data security is critical to consumers, and protecting it is a priority for the FTC, as it should be to every business in America.”

ChoicePoint is a publicly traded company based in suburban Atlanta. It obtains and sells to more than 50,000 businesses the personal information of consumers, including their names, Social Security numbers, birth dates, employment information, and credit histories.

The FTC alleges that ChoicePoint did not have reasonable procedures to screen prospective subscribers, and turned over consumers’ sensitive personal information to subscribers whose applications raised obvious “red flags.” Indeed, the FTC alleges that ChoicePoint approved as customers individuals who lied about their credentials and used commercial mail drops as business addresses. In addition, ChoicePoint applicants reportedly used fax machines at public commercial locations to send multiple applications for purportedly separate companies.

According to the FTC, ChoicePoint failed to tighten its application approval procedures or monitor subscribers even after receiving subpoenas from law enforcement authorities alerting it to fraudulent activity going back to 2001.

The FTC charged that ChoicePoint violated the Fair Credit Reporting Act (FCRA) by furnishing consumer reports – credit histories – to subscribers who did not have a permissible purpose to obtain them, and by failing to maintain reasonable procedures to verify both their identities and how they intended to use the information.

The agency also charged that ChoicePoint violated the FTC Act by making false and misleading statements about its privacy policies. Choicepoint had publicized privacy principles that address the confidentiality and security of personal information it collects and maintains with statements such as, “ChoicePoint allows access to your consumer reports only by those authorized under the FCRA . . . ” and “Every ChoicePoint customer must successfully complete a rigorous credentialing process. ChoicePoint does not distribute information to the general public and monitors the use of its public record information to ensure appropriate use.”

The stipulated final judgment and order requires ChoicePoint to pay $10 million in civil penalties – the largest civil penalty in FTC history – and to provide $5 million for consumer redress. It bars the company from furnishing consumer reports to people who do not have a permissible purpose to receive them and requires the company to establish and maintain reasonable procedures to ensure that consumer reports are provided only to those with a permissible purpose. ChoicePoint is required to verify the identity of businesses that apply to receive consumer reports, including making site visits to certain business premises and auditing subscribers’ use of consumer reports.

The order requires ChoicePoint to establish, implement, and maintain a comprehensive information security program designed to protect the security, confidentiality, and integrity of the personal information it collects from or about consumers. It also requires ChoicePoint to obtain, every two years for the next 20 years, an audit from a qualified, independent, third-party professional to ensure that its security program meets the standards of the order. ChoicePoint will be subject to standard record-keeping and reporting provisions to allow the FTC to monitor compliance. Finally, the settlement bars future violations of the FCRA and the FTC Act.

This case is being brought with the invaluable assistance of the U.S. Department of Justice and the Securities and Exchange Commission.

The Commission vote to accept the settlement was 5-0.

NOTE: A stipulated final judgment and order is for settlement purposes only and does not constitute an admission by the defendant of a law violation. Consent judgments have the force of law when signed by the judge.

Also check out:

Technorati tags: :: :: :: ::

UPDATE: Added NYT link (20060127)

Monday, January 23, 2006

Techniques of the phone record brokers

Paul McNamara in Network World writes about how companies that sell phone records get the info. Apparently, many use the little info they collect to get a fuller profile on ChoicePoint or Lexis. With all that info, they can fool customer service reps into believing they are dealing with the actual customer. Some use corrupt phone company employees, some of whom advertise their availability on websites frequented by the record brokers. Check it out: How phone records are stolen

Technorati tags: :: :: .

Saturday, December 24, 2005

Handle your incident well and good publicity may follow

Being involved in an incident in which the records of two million customers go astray is not at all pleasant. But the good news is that, if you handle it right, you may actually get some good publicity. Case in point:

Three Cheers for ABN - Yahoo! News:

... So now for the good news: ABN AMRO is run by a bunch of standup folks, and the gents at DHL aren't far behind. True, I could criticize ABN for failing to, say, task a VP to personally cart its data tapes from warehouse to warehouse, and for instead shipping this valuable information like so many pounds of unwanted fruitcake. I could also place DHL in the same butterfingers basket at UPS. But in honor of the holiday season, I'll say instead what these companies did right.

DHL, for its part, upon learning on Nov. 18 that a data tape had gone missing, left no stone unturned trying to find it -- and ultimately did find it after a monthlong search. ABN gets credit for helping in the search and for (relatively) quickly informing its at-risk customers of the loss. But ABN gets extra credit for what it did after DHL found the tape.

Although the package containing the data tape was discovered apparently unopened, ABN volunteered to pay for one full year of credit monitoring for each of its 2 million clients who might conceivably have had their data compromised. That beats out Citigroup's June offer by 275 days, and it matches the offers from Ameritrade, ChoicePoint, and Reed.

Finally, ABN has determined that it will not let this situation ever happen again. For here on out, the company announced last week that it will discontinue outsourced shipping of sensitive personal data on tapes and switch to using only encrypted electronic means to transfer such data. Welcome to the 21st century, ABN. I just wish you had more company.

Tuesday, December 20, 2005

Data Privacy Issues to Persist Next Year

On the data privacy front, the new year will bring more of the same, according to eWeek:

Data Privacy Issues to Persist Next Year:

"People may remember 2005 as the year that corporate America woke up to the problem of data breaches and the importance of data privacy. Data leaks at Bank of America Corp., LexisNexis' Seisint division, ChoicePoint Inc. and CardSystems Inc. fed headlines for months, spawned countless lawsuits on behalf of aggrieved consumers and provided the impetus for federal legislation--still pending--to protect consumer data. But what will 2006 bring?

More of the same, say leading security experts.

More than ever before, enterprise IT managers will have to fight a battle on two fronts next year. On one side, more sophisticated and targeted attacks from organized, online criminal groups will test networks in new ways that are hard to detect...."

Wednesday, December 07, 2005

Cornell University outlines security and privacy incident response plans

In response to a new New York law that requires notification of security and privacy breaches, Cornell University has issued the following media release outlining their plans for compliance:

Cornell complies with new state law on notification about stolen data:

By Bill Steele

If someone hacks into a Cornell University computer and pulls out personal and private information about members of the Cornell community, the people whose data has been compromised will be notified promptly, according to Cornell Information Technologies and the University Counsel's office.

Although the exact procedures have not been worked out, notification would be by ordinary mail, according to Norma Schwab, associate university counsel. E-mail notification, she said, is not legally adequate and might be unreliable, especially in an age when users are bombarded with "phishing" messages with subject lines like "your account has been compromised."

The notification plan is being developed by an ad hoc group called the Data Incident Response Team, which includes members from the Office of Information Technologies, the Office of University Counsel, Cornell Police and the University Audit Office. The group meets periodically to consider data security policy and comes together whenever there is a concern that sensitive data may have been accessed.

The action is in response to a New York state law, the Information Security Breach and Notification Act, passed in August and going into effect Dec. 8. The law requires any business -- including nonprofits -- that maintains personal and private data to provide notification when its systems are invaded and there is a reasonable belief that personal information might have been revealed. The kinds of data involved include Social Security and driver's license numbers and credit card information, and the notification requirement is intended to help consumers fend off possible identity theft.

"It made sense that we should let people know that we are complying with the new law," said Steve Schuster, director of information security. Schuster said he plans to take advantage of the opportunity to make Cornell staff more aware of their responsibilities to protect sensitive data.

"We're still in a state where our data resides in a lot of different areas," he explained. "We all have to take responsibility for it." In other words, sensitive information is not all on one university mainframe, but may also be on ordinary desktop computers in various departments. Schuster plans to require that all new staff members receive a policy and practices briefing -- a short version of the Travelers of the Electronic Highway course required for new students -- before they are issued net IDs. He hopes eventually to set up some sort of annual review of security procedures for all staff. For nontechnical staff, security measures include using strong passwords, protecting those passwords from disclosure and physically securing the computer.

University policies on security are being updated. The venerable Responsible Use of Electronic Communications policy is being expanded as Responsible Use of Information Technology Resources, and it will incorporate policies on data management and security. Data will be broken into three categories: regulated information for which state and federal laws require security, such as Social Security numbers and grades; "Cornell confidential" information, such as salaries and performance reviews; and public data. Security should be tailored to the level of confidentiality of the data. "It will be necessary for departments to inventory where these data reside in their systems," Schuster said.

Despite having very talented people around, higher education institutions are not immune to security breaks, Schuster pointed out. "In the first six months of 2005 there were 72 media-worthy computer compromises in the United States," he reported, "and slightly over half of them were in higher ed. We deal with break-ins here all the time, but we have a really good process in place."

The New York law, patterned on one passed about two years ago in California, was inspired by several incidents in which large corporate databases were compromised. In the most widely publicized case, ChoicePoint, a credential-verifying firm, allowed criminals to obtain personal data on some 140,000 people. At least 15 states have passed similar laws, and legislation is pending at the federal level.

Saturday, December 03, 2005

ChoicePoint in the spotlight again; seeking access to California drivers' records on behalf of DHS

The Los Angeles Times is reporting that the embattled ChoicePoint has garnered some additional publicity as it seeks to have access to the entire database maintained by the California Department of Motor Vehicles. It is seeking to have the usual DMV fees waived as it is seeking the records in order to serve its client, the Department of Homeland Security. A number of Californians are a little reluctant to have the state give access to the company that allowed identity thieves free rein in its other databases. The article also discusses some tussles with the Pennsylvania DMV. Check it out: Big Data Broker Eyes DMV Records - Los Angeles Times.

Thanks to Daniel Solove at Concurring Opinions for the link. Check out what he has to say as well: Concurring Opinions: ChoicePoint Wants Your Motor Vehicle Records.

Saturday, November 19, 2005

The Rootkit of All Evil

Dan Mitchell at the New York Times sums up some lessons learned from the Sony rootkit fiasco: The Rootkit of All Evil - New York Times. The same lessons apply for privacy problems (see Choicepoint, especially): "One, bloggers will catch you. And two, it's not the screw-up, it's the cover-up."

Saturday, November 12, 2005

ChoicePoint sells access to FBI and Pentagon to track terrorists and others

According to GovExec.com, a Freedom of Information Act request has revealed that embattled ChoicePoint has been providing extensive services to the FBI and the Defense Department, essentially providing access to its enormous databases that the US government would not be able to compile on its own.

www.GovExec.com - FBI, Pentagon pay for access to trove of public records (11/11/05):

"To help the government track suspected terrorists and spies who may be visiting or residing in this country, the FBI and the Defense Department for the past three years have been paying a Georgia-based company for access to its vast databases that contain billions of personal records about nearly every person -- citizens and noncitizens alike -- in the United States.

According to federal documents obtained by National Journal and Government Executive, among the services that ChoicePoint provides to the government is access to a previously undisclosed, and vaguely described, 'exclusive' data-searching system. This system in effect gives law enforcement and intelligence agents the ability to use the private data broker to do something that they legally can't -- keep tabs on nearly every American citizen and foreigner in the United States."

Thanks to beSpacfic for the link: beSpacific: Gov't Pays Aggregator for Access to Extensive Database of Personal Info.

Tuesday, November 08, 2005

ChoicePoint filing suggests further 17,000 affected consumers

ChoicePoint's most recent 10-Q filing with the SEC suggests that an additiona 17,000 consumers were affected by the high-profile data breach. See: ChoicePoint filing: 17,000 more may be fraud victims - 2005-11-08.

It's interesting to look at the filing itself, just to get a flavour of the cost of this issue to ChoicePoint and its impact upon their bottom line:

CHOICEPOINT INC (Form: 10-Q, Received: 11/08/2005 15:01:50):

Fraudulent Data Access

ChoicePoint’s review of the Los Angeles fraudulent data access described in the Company’s Form 10-K for the year ended December 31, 2004 and other similar incidents is ongoing. The Company currently expects that the number of consumers to which it will send notice of potential fraudulent data access will increase from the approximately 162,000 consumers it has notified to date, but the Company does not anticipate that the increase will be significant.

As previously disclosed in the Company’s Form 10-K for the year ended December 31, 2004, ChoicePoint is continuing to strengthen its customer credentialing procedures and is recredentialing components of its customer base, particularly customers that have access to products that contain personally identifiable information. Further, the Company continues to review and investigate other matters related to credentialing and customer use. The Company’s investigations as well as those of law enforcement continue. The Company believes that there are other instances that will likely result in notification to consumers. As previously stated, the Company intends for consumers to be notified, irrespective of current state law requirements, if it is determined that their sensitive personally identifiable information has been acquired by unauthorized parties. The Company does not believe that the impact from notifying affected consumers will be material to the financial position, results of operations or cash flows of the Company.

On March 4, 2005, ChoicePoint announced that the Company will discontinue the sale of certain information services that contain sensitive consumer data, including social security numbers, except (1) where there is either a specific consumer driven transaction or benefit, or (2) where such services serve as authentication or fraud prevention tools provided to large accredited customers with existing consumer relationships, or (3) where the services support federal, state or local government and law enforcement purposes. The Company cannot currently accurately estimate the future impact that the customer fraud, related events and the decision to discontinue certain services will have on our operating results and financial condition. The Company will review various technology investments in this small business segment as well as other related costs incurred in serving this segment.

ChoicePoint incurred $5.4 million ($3.3 million net of taxes) in the first quarter of 2005, $6.0 million ($3.7 million net of taxes) in the second quarter of 2005, and $4.0 million ($2.5 million net of taxes) in the third quarter of 2005 for specific expenses related to the fraudulent data access previously disclosed. Approximately $2.0 million of the $15.5 million total charges through September 30, 2005 were for communications to, and credit reports and credit monitoring for, individuals receiving notice of the fraudulent data access and approximately $13.5 million for legal expenses and other professional fees. The Company currently estimates that it will incur additional incremental expenses as a result of the fraudulent data access of approximately $3 to $5 million in the fourth quarter of 2005. In addition, the publicity associated with these events or changes in regulation may materially harm the business and ChoicePoint’s relationship with customers or data suppliers.

The Company is involved in several legal proceedings or investigations that relate to these matters, as described in “Legal Proceedings” of this Form 10-Q. ChoicePoint is unable at this time to predict the outcome of these actions. The ultimate resolution of these matters could have a material adverse impact on the financial results, financial condition, and liquidity and on the trading price of the Company’s common stock. Regardless of the merits and ultimate outcome of these lawsuits and other proceedings, litigation and proceedings of this type are expensive and will require that substantial Company resources and executive time be devoted to defend these proceedings.

Security Breaches and Misuse of Information Services

Security breaches in the Company’s facilities, computer networks, and databases may cause harm to ChoicePoint’s business and reputation and result in a loss of customers. Many security measures have been instituted to protect the systems and to assure the marketplace that these systems are secure. However, despite such security measures, the Company’s systems may be vulnerable to physical intrusion, computer viruses, attacks by hackers or similar disruptive problems. Users may also obtain improper access to the Company’s information services if they use stolen identities or other fraudulent means to become ChoicePoint customers or by improperly accessing ChoicePoint’s information services through legitimate customer accounts. If users gain improper access to ChoicePoint’s databases, they may be able to steal, publish, delete or modify confidential third-party information that is stored or transmitted on the networks. A security or privacy breach may affect ChoicePoint in a variety of ways, including but not limited to, the following ways:

  • deterring customers from using ChoicePoint’s products and services or resulting in a loss of existing customers;
  • deterring data suppliers from supplying data to the Company;
  • harming the Company’s reputation;
  • exposing ChoicePoint to litigation and other liabilities;
  • increasing operating expenses to correct problems caused by the breach;
  • affecting the Company’s ability to meet customers’ expectations;
  • causing inquiry from governmental authorities; or
  • legislation that could materially affect the Company’s operations.

The Company expects that, despite its ongoing efforts to prevent fraudulent or improper activity, in the future it may detect additional incidents in which consumer data has been fraudulently or improperly acquired. The number of potentially affected consumers identified by any future incidents is obviously unknown. "

Friday, November 04, 2005

US parties split on proposed data protection and notification laws

The Washington Post is continuing to chronicle the ongoing debate between the US political parties on proposals to implement a federal privacy law to protect consumers against indentity theft. Privacy advocates are very concerned that the process will result in a weak law that pre-empts much more rigorous state laws, such as that in California. The California law is largely responsible for the wave of publicity about privacy breaches in the last year.

Parties Split on Data-Protection Bill:

"... Under the bill, data brokers and other firms that store consumer data would have to notify consumers that their information was breached only when it was determined that a 'significant risk' of identity theft or other fraud might result.

That decision would be made by the company that was breached, which Democrats said was akin to having to no requirement at all.

This year alone, tens of millions of consumers have been notified of breaches at information brokers such as ChoicePoint Inc. and LexisNexis, financial institutions, government agencies, universities, online retailers and other firms.

Many notices were sent out under a California law that covers any firm doing business in the state.

'No notices would have gone out under the standard put forth in this bill,' which would preempt state laws, said Rep. Janice D. Schakowsky (D-Ill.). 'We would not have known how badly corporations treat personal information, nor would consumers have been able to take action to protect themselves -- even from financial identity theft -- if this bill had been in place in February 2005.'

Data brokers, direct marketers, financial institutions and several large technology companies supported the approach of the bill, as did FTC Chairman Deborah P. Majoras. They argue that thieves or hackers cannot always use data they might gain access to, and that bombarding consumers with notices every time a breach occurs would cause people to ignore them...."