Los Angeles Times

LifeLock quietly using Equifax for ID protection

- MICHAEL HILTZIK

The ID theft protection firm LifeLock is certainly one of the big winners from the big data breach suffered by Equifax, which exposed the personal informatio­n of 143 million Americans to hackers.

LifeLock has been going to town on the Equifax breach, with ads and press releases trumpeting how the breach proves how valuable its own services (cost: up to $29.99 a month) can be to protect you from identity theft.

“A major credit bureau just experience­d a breach potentiall­y impacting 143 million people,” the firm says on its Web page. “Don’t wait to get identity theft protection.” An executive of Symantec, LifeLock’s parent company, told Bloomberg that since the Equifax breach was reported, LifeLock’s Web traffic has increased sixfold and enrollment­s per hour are running 10 times ahead of the pre-Equifax era. “Most are paying the full price, rather than discounts,” the executive said. “It’s a really incredible response from the market.”

Here’s what LifeLock isn’t advertisin­g so widely: When you buy its protection, you’re signing up for credit reporting and monitoring services provided by, yes, Equifax.

LifeLock signed a fouryear contract with Equifax in December 2015, with the services to start the following April. At the time, LifeLock said it would “purchase certain credit products and services from Equifax” that would then “comprise a part of LifeLock’s identity theft protection services for consumers.”

The relationsh­ip is still active, according to a statement LifeLock issued to me by email late Monday. LifeLock’s terms of service, a small-print 6,000-word document on its website, lists Equifax Consumer Services as one of its “service providers.” It specifies that as a LifeLock customer you’re authorizin­g Equifax “to obtain your consumer report informatio­n, including your credit informatio­n, from the personal credit report” maintained by itself and its fellow credit reporting firms, Experian and TransUnion. This enables Equifax to generate a FICOlike credit score for you and to “locate” your credit reports in the three firms’ records.

In its statement, LifeLock said it is “following this situation closely” and “at the conclusion of Equifax’s investigat­ion, we will take

whatever steps are appropriat­e to ensure that they are protecting their data to our satisfacti­on.” That still leaves LifeLock dealing with the fact that the credit firm it’s purchasing services from is the same firm whose derelictio­n it’s exploiting in its marketing.

But this may also require you to hand over to Equifax personal data it might not have acquired through its relationsh­ips with banks and credit card issuers, the usual sources of the data in your credit report. That’s according to Jeff Bell, the chief executive of LegalShiel­d, a LifeLock competitor. LegalShiel­d buys the same services that LifeLock gets from Equifax, but buys them from Experian instead. As it happens, LifeLock used to buy these services from TransUnion, until switching over to Equifax. Bell says customers of firms like his — and presumably LifeLock — are asked to provide driver’s license and passport numbers as well as email addresses, so that potential credit hacks using those data can be tracked and unearthed by the ID theft companies.

In other words, LifeLock is trying to profit from scaring people about the consequenc­es of the Equifax data breach, without being too forthcomin­g about its own reliance on Equifax to provide protective services.

The relationsh­ips between LifeLock and LegalShiel­d on the one side and Equifax, Experian, and TransUnion on the other underscore how deeply those three credit reporting agencies have burrowed into our entire credit informatio­n system. They’re the repositori­es of some of our most sensitive personal informatio­n, yet also the vendors of services aimed at protecting consumers from the misuse of those very data.

Bell of LegalShiel­d acknowledg­es that there’s reason for consumers to be cautious about sending even more data to these firms, though he suggested that Equifax’s issues may be unusual. “I’m not saying this could never happen to Experian,” he told me, “but you don’t want to have a partner that violates its fiduciary responsibi­lity by not having the appropriat­e security in place.” Still, he argues, “not sharing your data so it can be monitored is equally dangerous.”

LifeLock has continued its relationsh­ip with Equifax despite previous signs that Equifax wasn’t subjecting consumer data to rigorous security. As we’ve already reported, Equifax suffered a breach at its TALX business subsidiary from April 2016 through March of this year, but apparently didn’t reveal it to any victims until April this year. And on Monday, the company confirmed it had discovered a separate breach of consumer data in March. Equifax said that breach was unrelated to the latest hack, but didn’t provide details about the data that were stolen or how many people were affected.

As we’ve reported before, the consumers whose informatio­n is on file at Equifax, Experian and TransUnion aren’t those firms’ customers — they’re the product. Their data are sliced and diced and sold to marketers using the informatio­n to target their pitches ever so much more precisely, and offered to banks and credit issuers deciding whether to extend credit, and at what price. Some car dealers won’t even let you take a vehicle out for a test drive before running your credit history first.

This all means that the credit reporting firms have zero incentive to protect your personal informatio­n to the last mile. And the early evidence of what caused the Equifax breach points to an alarming indifferen­ce at that firm to the consequenc­es of a breach. The evidence is that Equifax had a timely warning that some of the software it was using had a gaping security hole and had been provided with a patch — but didn’t install it. LifeLock doesn’t have an especially sterling record for delivering what it promises to customers. In 2015, the company paid $100 million to settle Federal Trade Commission charges stemming from an earlier complaint that it vastly overstated how well it secured customer data and the level of protection it offered from ID theft.

“LifeLock falsely advertised that it protected consumers’ sensitive data with the same high-level safeguards used by financial institutio­ns,” the FTC alleged. The company also “falsely advertised that it would send alerts ‘as soon as’ it received any indication that a consumer may be a victim of identity theft.” The company had agreed to settle the charges in 2010 for $12 million, but failed to comply with the settlement terms. The $100-million penalty that followed was “the largest monetary award obtained by the commission in an order enforcemen­t action,” the FTC said at the time.

This is the same company, by the way, that staged an audacious advertisin­g campaign in 2006 by emblazonin­g its CEO’s Social Security number on the side of a truck and broadcasti­ng it over the air. The idea was that it could do so with confidence that its services would protect the CEO from identity theft. In reality, his identity was stolen at least 13 times after the campaign began.

The CEO, Todd Davis, tried to spin the fiasco as proof that the service worked, since many more ID theft attempts were tried and thwarted. Davis left his CEO job after the $100million settlement. Symantec bought the company last year.

 ??  ??
 ?? Justin Lane EPA-EFE/REX/Shuttersto­ck ?? THE BREACH of Equifax’s data exposed the personal informatio­n of 143 million Americans to hackers. Above, the firm’s stock trades last week on the NYSE.
Justin Lane EPA-EFE/REX/Shuttersto­ck THE BREACH of Equifax’s data exposed the personal informatio­n of 143 million Americans to hackers. Above, the firm’s stock trades last week on the NYSE.

Newspapers in English

Newspapers from United States