Experian, T-Mobile US settle data spills for mere $16m
(2022/11/08)
- Reference: 1667926806
- News link: https://www.theregister.co.uk/2022/11/08/experian_tmobile_fined_over_2012/
- Source link:
Experian and T-Mobile US have reached separate settlements with 40 states in America following a pair of data security breaches in 2012 and 2015. The settlement will net authorities $16 million, along with assurances it won't happen again.
Experian will be bearing the largest brunt of the fine, with $14 million coming from the credit reporting company.
Led by attorneys general from Massachusetts and Illinois, [1]the settlements stem from a pair of data breaches at Experian in 2012 and 2015, the latter of which [2]T-Mo was caught up in .
[3]
The [4]2012 breach at Experian were revealed following a notification to the US Secret Service. Experian bought a company called Court Ventures, Inc., and all of its customers, one of whom was an identity thief. That crook has since plead guilty to wire fraud, identity fraud and other crimes, including falsely representing himself as a private investigator to gain access to Experian systems.
[5]
[6]
All the data collected by that single intruder was handed to other nefarious parties, who made over 3 million queries for personal information against data owned by CVI and Experian.
Experian gave no notice to affected consumers or state authorities regarding the incident.
[7]
In [8]2015 , the consumer credit reporting company was hit again. This time the attacker managed to gain access to a portion of Experian's network where T-Mobile US stored data used to process customer applications. As a [9]result of that attack , the data of 15 million people – including Social Security numbers, other ID numbers, name, address and birthdate – was stolen.
T-Mo and Experian notified customers of that attack, and Experian offered free credit reporting services, as is usually the case when a large company has that volume of personally identifiable information stolen.
Wrist, meet slap
Along with startlingly small financial penalties, Experian is being forced to provide an additional five free years of credit monitoring on top of two years it previously awarded in wake of the 2015 breach, as well as two free credit reports annually.
In addition, the credit bureau's settlement included requirements that it maintain an incident response and data breach notification plan, develop an identity theft prevention program, and do proper due diligence in vetting people with access to data, including reassessing access after an acquisition.
Experian was also told not to "misrepresent to its clients the extent to which [it] protects the privacy and security of personal information."
[10]
T-Mobile US, meanwhile, was told to improve its vendor management oversight and develop a compliance program that ensures third parties with access to customer PII are storing it properly.
Whether either company has learned from those breaches is unclear, especially in light of subsequent incidents at both companies.
In 2020, Experian reported it had handed data including PII for [11]24 million South Africans to another individual who falsely representing themselves in order to gain access. Despite assurances that the data had been recovered and destroyed, it later [12]showed up online .
[13]15 MILLION T-Mobile US customer records swiped by hackers
[14]Experian says it recovered and deleted data on 24 million South Africans after giving it to random 'marketing' person
[15]Personal data from Experian on 40% of South Africa's population has been bundled onto a file-sharing website
[16]T-Mobile US to cough up $550m after info stolen on 77m customers
Last year, T-Mobile US was attacked again and [17]77 million customer records were stolen. T-Mobile paid out $550 million to settle that case. Startlingly, it's T-Mo's [18]fifth acknowledged breach in four years.
To put its latest $2.43 million fine in perspective, the Un-Carrier reported a net income of $508 million in Q3 of this year. Experian, facing $13.67 million in fines, made around [19]$6.2 billion in FY 22 [PDF].
"I am pleased to join my colleagues today in holding these companies accountable for their failures to protect the sensitive information of our residents," said Massachusetts AG Maura Healey. ®
Get our [20]Tech Resources
[1] https://www.mass.gov/news/ag-healey-secures-16-million-from-multistate-settlements-with-experian-and-t-mobile-over-data-breaches
[2] https://www.theregister.com/2015/10/01/experian_tmobile_breach/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y2rfiilyfZv-NnKyK3gAPAAAAIs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.mass.gov/doc/experian-court-ventures-aod-massachusetts
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y2rfiilyfZv-NnKyK3gAPAAAAIs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y2rfiilyfZv-NnKyK3gAPAAAAIs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y2rfiilyfZv-NnKyK3gAPAAAAIs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://www.mass.gov/doc/experian-2015-data-breach-aod-massachusetts
[9] https://www.t-mobile.com/news/blog/experian-data-breach
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y2rfiilyfZv-NnKyK3gAPAAAAIs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://www.theregister.com/2020/08/20/experian_24m_south_africans_data_breach/
[12] https://www.theregister.com/2020/09/14/south_africa_experian_data_breach_wesendit/
[13] https://www.theregister.com/2015/10/01/experian_tmobile_breach/
[14] https://www.theregister.com/2020/08/20/experian_24m_south_africans_data_breach/
[15] https://www.theregister.com/2020/09/14/south_africa_experian_data_breach_wesendit/
[16] https://www.theregister.com/2022/07/25/tmobile_to_pay_550m_data_breach/
[17] https://www.theregister.com/2022/07/25/tmobile_to_pay_550m_data_breach/
[18] https://www.newsweek.com/t-mobile-hacked-5th-time-4-years-latest-breach-nearly-50-million-affected-1620710
[19] https://www.experianplc.com/media/4412/experian-fy22-full-year-results-presentation.pdf
[20] https://whitepapers.theregister.com/
Experian will be bearing the largest brunt of the fine, with $14 million coming from the credit reporting company.
Led by attorneys general from Massachusetts and Illinois, [1]the settlements stem from a pair of data breaches at Experian in 2012 and 2015, the latter of which [2]T-Mo was caught up in .
[3]
The [4]2012 breach at Experian were revealed following a notification to the US Secret Service. Experian bought a company called Court Ventures, Inc., and all of its customers, one of whom was an identity thief. That crook has since plead guilty to wire fraud, identity fraud and other crimes, including falsely representing himself as a private investigator to gain access to Experian systems.
[5]
[6]
All the data collected by that single intruder was handed to other nefarious parties, who made over 3 million queries for personal information against data owned by CVI and Experian.
Experian gave no notice to affected consumers or state authorities regarding the incident.
[7]
In [8]2015 , the consumer credit reporting company was hit again. This time the attacker managed to gain access to a portion of Experian's network where T-Mobile US stored data used to process customer applications. As a [9]result of that attack , the data of 15 million people – including Social Security numbers, other ID numbers, name, address and birthdate – was stolen.
T-Mo and Experian notified customers of that attack, and Experian offered free credit reporting services, as is usually the case when a large company has that volume of personally identifiable information stolen.
Wrist, meet slap
Along with startlingly small financial penalties, Experian is being forced to provide an additional five free years of credit monitoring on top of two years it previously awarded in wake of the 2015 breach, as well as two free credit reports annually.
In addition, the credit bureau's settlement included requirements that it maintain an incident response and data breach notification plan, develop an identity theft prevention program, and do proper due diligence in vetting people with access to data, including reassessing access after an acquisition.
Experian was also told not to "misrepresent to its clients the extent to which [it] protects the privacy and security of personal information."
[10]
T-Mobile US, meanwhile, was told to improve its vendor management oversight and develop a compliance program that ensures third parties with access to customer PII are storing it properly.
Whether either company has learned from those breaches is unclear, especially in light of subsequent incidents at both companies.
In 2020, Experian reported it had handed data including PII for [11]24 million South Africans to another individual who falsely representing themselves in order to gain access. Despite assurances that the data had been recovered and destroyed, it later [12]showed up online .
[13]15 MILLION T-Mobile US customer records swiped by hackers
[14]Experian says it recovered and deleted data on 24 million South Africans after giving it to random 'marketing' person
[15]Personal data from Experian on 40% of South Africa's population has been bundled onto a file-sharing website
[16]T-Mobile US to cough up $550m after info stolen on 77m customers
Last year, T-Mobile US was attacked again and [17]77 million customer records were stolen. T-Mobile paid out $550 million to settle that case. Startlingly, it's T-Mo's [18]fifth acknowledged breach in four years.
To put its latest $2.43 million fine in perspective, the Un-Carrier reported a net income of $508 million in Q3 of this year. Experian, facing $13.67 million in fines, made around [19]$6.2 billion in FY 22 [PDF].
"I am pleased to join my colleagues today in holding these companies accountable for their failures to protect the sensitive information of our residents," said Massachusetts AG Maura Healey. ®
Get our [20]Tech Resources
[1] https://www.mass.gov/news/ag-healey-secures-16-million-from-multistate-settlements-with-experian-and-t-mobile-over-data-breaches
[2] https://www.theregister.com/2015/10/01/experian_tmobile_breach/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y2rfiilyfZv-NnKyK3gAPAAAAIs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.mass.gov/doc/experian-court-ventures-aod-massachusetts
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y2rfiilyfZv-NnKyK3gAPAAAAIs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y2rfiilyfZv-NnKyK3gAPAAAAIs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y2rfiilyfZv-NnKyK3gAPAAAAIs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://www.mass.gov/doc/experian-2015-data-breach-aod-massachusetts
[9] https://www.t-mobile.com/news/blog/experian-data-breach
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y2rfiilyfZv-NnKyK3gAPAAAAIs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://www.theregister.com/2020/08/20/experian_24m_south_africans_data_breach/
[12] https://www.theregister.com/2020/09/14/south_africa_experian_data_breach_wesendit/
[13] https://www.theregister.com/2015/10/01/experian_tmobile_breach/
[14] https://www.theregister.com/2020/08/20/experian_24m_south_africans_data_breach/
[15] https://www.theregister.com/2020/09/14/south_africa_experian_data_breach_wesendit/
[16] https://www.theregister.com/2022/07/25/tmobile_to_pay_550m_data_breach/
[17] https://www.theregister.com/2022/07/25/tmobile_to_pay_550m_data_breach/
[18] https://www.newsweek.com/t-mobile-hacked-5th-time-4-years-latest-breach-nearly-50-million-affected-1620710
[19] https://www.experianplc.com/media/4412/experian-fy22-full-year-results-presentation.pdf
[20] https://whitepapers.theregister.com/
Re: Maybe 1 penny per spam
the spectacularly refined chap
Bollocks. There's so much that doesn't ring true here that I simply can't enumerate it.
If you had the evidence you describe it'd be a slam dunk in court or for any regulator. I very much doubt any hacker expecting a profit would have a "database" on the host system to gain access to with your expert knowledge, it'll be a simple list to blast through.
I could carry on more or less forever but the bell for last orders has just gone.
Maybe 1 penny per spam
I've received maybe 200 SMS spams for fake stores hosted by a gang with a consistent hosting combination of Namecheap, Salesforce, Amazon, Cloudflare, High Speed Web, and Google. Some of those systems have trivial APIs that can be browsed to examine the database. My information source was listed as T-Mobile.
I'd like to give a special F-U to T-Mo for leaking my data and the lawyers for making sure there's no meaningful compensation. That's on top of the ongoing F-U to Namecheap, Salesforce, Amazon, Cloudflare, High Speed Web, and Google for playing dumb (or being authentically dumb) when they receive an abuse complaint.