Unauthorised RAC staffer harvested customer details then sold them to accident claims management company
- Reference: 1610376305
- News link: https://www.theregister.co.uk/2021/01/11/rac_staffer_unauthorised_computer_access/
- Source link:
Kim Doyle pleaded guilty to charges of conspiracy to secure unauthorised access to computer data and cashing in on RAC punters' personal information that she passed to William Shaw, director of TMS (Stratopsphere), trading as LIS Claims. Doyle was sentenced at Manchester Crown Court on Friday, 8 January.
[1]
The court heard that Doyle, 33, of Village Lane, Higher Whitley, North West England, generated lists of data on road traffic accidents, including partial names, mobile phone numbers and registration numbers, even though she was not given consent by the RAC to do so.
Shaw, 32, of Flixton Road, Urmston, near Manchester, also pleaded guilty to conspiracy to secure unauthorised access to computer data, and saw his sentence suspended for two years following an investigation and case brought by the [2]Information Commissioner's Officer (ICO), the UK data watchdog.
The ICO said there is evidence that the information sold to LIS Claims was subsequently used to make nuisance calls, one of which reached a driver at fleet management company Arval. That driver had been in an accident and the RAC carried out the recovery of the vehicle, raising suspicions of a data leak at RAC.
The RAC then ran a data leakage scan of its Outlook mailboxes and discovered a trail that led it to find Doyle's unauthorised lists of customer data.
Mike Shaw, head of criminal investigations at the ICO, issued a canned statement, saying this is not a victimless crime as they have a "detrimental impact" on the public and businesses.
"People's data is being accessed without consent and businesses are putting resources into tracking down criminals. Once the data is in the hands of claims management companies, people are subjected to unwanted calls which can in turn lead to fraudulent personal injury claims," said Shaw.
"This case shows that we can, and will take action, and that could lead to a prison sentence for those responsible. Where appropriate we will work with partner agencies to make full use of the Proceeds of Crime Act to ensure that criminals do not benefit financially from their criminal behaviour."
The court has issued a Confiscation Order under which Doyle must pay £25,000, and Shaw has been ordered to cough £15,000, both within three months. Should they fail to pay these sums they will be jailed for three months.
Both were also ordered to carry out 100 hours of unpaid work and contribute £1,000 towards costs.
[3]
The RAC told The Register : "We take our responsibility for protecting personal data extremely seriously and take a zero-tolerance approach to any misuse of personal data. As such, we worked closely with the Information Commissioner's Office, both before and during its investigation." ®
Get our [4]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x250%7C300x252%7C300x600&tile=3&c=33X-yEKMGotySHdBV@qJQ7RwAAAAY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dtop%26test%3D0
[2] https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2021/01/motor-industry-employee-sentenced-in-ico-computer-misuse-act-prosecution/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x100%7C300x250%7C300x251&tile=4&c=44X-yEKMGotySHdBV@qJQ7RwAAAAY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://whitepapers.theregister.com/
Re: Competition for the RAC?
Yes they do but legally.
They'd be hauled up on similar charges if that resulted in a breach of the rules, hopefully with all directors sharing the personal pain.
Re: Competition for the RAC?
The only sin is that the chick was caught pilfering data that RAC already sells legally.
In the US, she'd be fired and that's it.
No charges.
The sad thing is that if you look at the T&Cs you give these companies the ability to do this. You have no choice because they all do it.
And its not just RAC. Other companies do it.
Re: Competition for the RAC?
You are joking.
The RAC are too big for that. "Lessons would be learned".
There are senior executives involved - different rules apply.
Re: Competition for the RAC?
They do sell it but only if you've checked the box that says you authorize them to pass on your data to trusted partners. Remember this stuff is strictly opt in by law.
Although I suspect that now we are out of the EU it won't be long before this becomes opt out. With the only way to opt out being to send them a letter countersigned by the prime minister.
To discourage any others
This is a good start.
Not even close to a strict enough punishment.
Both should have been subject to hefty fines as both will almost certainly have gained financially from the arrangement. Then the claims management company should have been subject to a significant fine.
Finally the RAC should have been fined. Yes they co-operated. Yes they caught the rogue employee. The reason that they should be fined is that their systems allow the bulk export of data. I remember years ago being a member of a corporate data protection board I explained to one department that their systems allowed personal data to be exported in bulk which was in breach of our data protection declaration. I pointed out that one default report included customer names, addresses, phone numbers, email addresses and bank details. I asked the the idiot (sorry department manager) why this was necessary and he could not provide a single instance where having all that data together in a handy spreadsheet was necessary. In this particular case there should be no reason why a report containing the customer names (albeit partial) and mobile numbers in a single bulk report should be necessary.
The reason that they should be fined is that their systems allow the bulk export of data.
Exactly. Remember all those "we lost a CD with 100,000 names, NI numbers and addresses on it" incidents? So many systems just store everything in plain text for anybody to download, instead of requiring a single lookup key to find a single item. It would be a lot easier to secure people's data if the sensitive parts were stored as hashes so that they could only be used as lookup keys. But even in the credit card world, people use workarounds so they can view actual numbers, rather then inputting them into the query to see if a given card is valid. Many data hosting services have to spend significant time purging out anything that looks like a plaintext CC number.
1. Read the article. They have both been "fined". Failure to pay results in a prison sentence.
2. Where does it say bulk export? She could easily have sent an email everytime she dealt with it. If she is a call handler, then sending out details of names, addresses and other persobal details would be part of her job, so again no easy read flags.
1. No they weren't fined. Those were just orders to reclaim the profit they had made. The point about fines is that they should be punishments rather than just orders to repay the money you have made. The latter is not really much of a punishment as it just takes you back to square one. Also these are often based on underestimates of the amount of money received if no records are available - and it would be a pretty special kind of criminal that kept detailed records of their misdeeds.. And the additional grand is contribution to legal costs rather than a fine.
2. If she was doing for cases she'd handled then she would have had more information than partial names and mobile numbers.
When it comes to financial penalties remember that the ICO has had the power to levy unlimited fines since 2015.
These type of activity is a plague on humanity
I for one, am glad this type of activity is being investigated and reasonably thoroughly, whether the penalties applied here are sufficient, remains to be seen, but having a suspended sentence is not going to help with onward employment surely?
Speaking from experience, I was plagued by claims management parasites after being involved in an accident some years ago. It's frustrating to say the least when your phone is going off constantly with spurious calls purporting to be the "Claims Management Company", I'm sure the myriad databases the insurance industry uses are being mined, legally or otherwise, and I object to my information being farmed out.
Perhaps this incident will help drive this sub culture away? One can only hope!!
Re: These type of activity is a plague on humanity
Rather than "claims management company" I've had two types in the past.
Number one "I am calling on behalf of your insurance company" to which a good response is to ask them for the name of your insurance company. Due to the nature of the data they often won't know it.
Number two "I am calling about the motor accident you had in the last three years". Clearly these buggers are as dodgy as possible and the best response is to simply hang up. Or if you have nothing else to do string them along and waste as much of their time as you possibly can.
Seriously though I had an accident earlier this year and received an iffy looking letter from a solicitor which wasn't very clear about what they were trying to reclaim and from who. I called the my insurer who explained that the letter was from a solicitor who they had engaged to try to recover my excess from the third parties insurer (this wasn't clear it looked as if they were trying to recover it from me) and that they should never have written to me as it wasn't really of any consequence to me. So sometimes insurers do employ third parties to manage claims or parts thereof, but these companies should not be communicating direct with you they should always do so through your insurance company unless your insurers have informed you of it before. As such I am told the best way to deal with any of these companies is to refer them to your insurer. If they are not happy with this or try the "but your insurer asked us to contact you direct" ask them for their name, company name and phone number along with their case number and tell them you'll be calling your insurers to authorise the call. Explain that if the insurer do authorise the call you'll be calling them straight back, otherwise you'll be calling the police and the ICO. This tactic will generally be rewarded with a rapidly terminated call.
Re: These type of activity is a plague on humanity
Regarding #2
I've been plagued by these calls with the same MO since an accident in 2014. A couple of months ago, rather than concoct some elaborate story involving donkeys, rainbows, etc, I sensed that I was speaking to someone with a conscious. "But I don't have a car. In fact, I've never had a car...." along with, "if you could be kind enough to take me off your database, I'd be eternally grateful."
Touch wood (oo-er) I've not received another call.
Re: These type of activity is a plague on humanity
Yep - I had a claims adjustment guy, phoning from Liverpool when I live in London, saying " Now we've inspected your lovely motor all you need to do is approve this..."
You'd think I had a flash Jag or a Beemer, nope.
Nothing to link him to the insuracne company either.
Re: These type of activity is a plague on humanity
It is not just those who had an accident who get a parasite call. I dashed to answer my wife's phone when she was unable to answer quickly when expecting a legitimate call from a known source. Instead, it was a damned parasite 'false claims company', they got no further before being told to b*gg*r off. Perhaps I should report the sods to ICO.
This stuff is not unique to the RAC but the ICO seem to have difficulty tracking down the perps. In this case it seems that they only got a result because a victim managed to point the finger at the RAC as the source of the leak.
I tried to raise a case once after a similar call about a car accident. It was clear the caller had some details but they were very limited. This then led me to believe that the had come by the data by nefarious means. If they had a right to the data it would have been much more complete. However I was told that I could only make a report of a data breach if I could provide the name of the company who had suffered the breach. The trouble is that the data could have come from a number of sources, my insurer, the third party's insurer, the company who'd towed the car, the body shop who assessed the car, the company that collected the write off and perhaps a few subcontractors as well. I explained this but was told that without a specific company name there was nothing that could be done. Since there was no way I could identify the source of the leak (all they seemed to have was my name, phone number and strangely the month of the accident - not the full date) there was no way I could procede.
However given those three specific items of data you'd think the ICO would have been able to work out which of the companies was the most likely source since they could surely ask to see the reports. After all it seems somebody had got hold of a monthly report that included partial names (they only used my surname), and phone number. Obviously there was probably more information than that on the report, but nothing they would have found useful to give me on the call. As such you're looking at it being unlikely to be my insurer as they would have had more personal information. However all of the others were likely to have that data, but no other personal data. The other thing all of them would have had would have been my registration number, but strangely that was never mentioned on the call. But then maybe that wasn't included in the particular report that was leaked. To look at it another way it could even have been something as simple as a phone record. It if was the latter then my insurer, the tow company and the body shop all called me on that number and knew my surname. But once again this apparently wasn't enough for the ICO.
The ICO needs 1. More teeth and 2. KPIs to work on. If they had a clear up rate they had to meet I'm sure they would try harder.
Sounds recognisable. In my case I was pretty sure it was the (big name) car hire company my loan car came from after my car was in an accident. Only them and the Insurance company knew the details in the phone call. It was a few years back now so I can't remember the details of why I was certain it was the car hire people.
I assume it is the ambulance chasers who approach the staff at places like this. Pay them for tip-offs.
I had forgotten the car hire firm. The courtesy car was delivered by a car hire firm and they would have had my name and phone number but no other details of the accident.
In my case I was pretty sure it was the (big name) car hire company my loan car came from after my car was in an accident.
Correlation is not causation. I've been called by an automated system where a girl says "I believe that you have been involved in an accident that wasn't your fault. Is that correct?" If you say "yes" or possibly make any noise whatsoever you get connected through to a real person (different voice) who wants to be your best friend and gather all your personal details. As I hadn't been involved in an accident I had great fun telling them that I had and not giving them anything else.
Only 8 months suspended?
These cases are so hard to investigate and uncover it's disappointing an example is not made of the few actually caught and prosecuted.
Once upon a time you had to be a proper law firm - well solicitors - to carry out this sort of work. But the law changed and "claims management" companies came into being. They don't have to registered with anybody and don't have a regulatory body. Then people are surprised when they turn out to be dodgy.
There are trade bodies and regulatory frameworks for solicitors and insurers, but no such thing for these "claims management" companies. The simple solution would be to make them sign up to the same system as insurers. Half of them would go out of business overnight as they wouldn't want the extra expense.
These two should have done time - it has to be taken seriously.
And the RAC need a hefty fine for having a lousy data protection scheme.
Then forced
To buy a new battery for their cars
Makes a mockery of the law...
... when there is no difference between RAC selling it to scammers and a single person doing the same for personal profit.
Competition for the RAC?
Don't the RAC already sell this stuff?