DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

FCC jumps into data security; plans $10 million fine for carriers that breached consumer privacy

Posted on October 24, 2014 by Dissent

Back in 2013, I blogged about a breach involving TerraCom and YourTel. Their breach response was so poor that I devoted two posts to criticizing them. But as bad as the breach and their response were, things got even worse when Scripps News kept investigating and uncovered more problems. It was no surprise, therefore, to learn that the Indiana Attorney General was investigating.

What is a surprise, however, is an announcement today by FCC that they intend to fine TerraCom and YourTel $10 million:

This is an unofficial announcement of Commission action. Release of the full text of a Commission order constitutes official action.

See MCI v. FCC. 515 F 2d 385 (D.C. Cir. 1974).

FCC PLANS $10 MILLION FINE FOR CARRIERS THAT BREACHED CONSUMER PRIVACY

TerraCom and YourTel Allegedly Stored Customers’ Personal Information Online in a Format Accessible Through Routine Internet Search

Washington, D.C. – The FCC intends to fine TerraCom, Inc. and YourTel America, Inc. $10 million for several violations of laws protecting the privacy of phone customers’ personal information. According to an investigation by the Enforcement Bureau, TerraCom and YourTel apparently stored Social Security numbers, names, addresses, driver’s licenses, and other sensitive information belonging to their customers on unprotected Internet servers that anyone in the world could access. The information was gathered to demonstrate eligibility for the Lifeline program, which is a Universal Service Fund program that provides discounted phone services for low-income consumers. The companies allegedly breached the personal data of up to 305,000 consumers through their lax data security practices and exposed those consumers to identity theft and fraud. This is the Commission’s first data security case and the largest privacy action in the Commission’s history.

“Consumers trust that when phone companies ask for their Social Security number, driver’s license, and other personal information, these companies will not put that information on the Internet or otherwise expose it to the world,” said Travis LeBlanc, Chief of the FCC’s Enforcement Bureau. “When carriers break that trust, the Commission will take action to ensure that they are held accountable for unjust and unreasonable data security practices.”

In their privacy policies, the two companies stated that they had in place “technology and security features to safeguard the privacy of your customer specific information from unauthorized access or improper use.” Yet, from September 2012 through April 2013, the sensitive documents they collected from consumers were apparently stored in a format accessible via the Internet and readable by anyone. Ultimately, the personal information of up to 305,000 low-income consumers was apparently exposed to public view. Yet even after the companies learned of this security breach, they allegedly failed to notify all potentially affected consumers, depriving them of any opportunity to take steps to protect their personal information from misuse by Internet thieves.

The Commission alleges that the carriers’ failure to reasonably secure their customers’ personal information violates the companies’ statutory duty under the Communications Act to protect that information, and also constitutes an unjust and unreasonable practice in violation of the Act, given that their data security practices lacked “even the most basic and readily available technologies and security features and thus creates an unreasonable risk of unauthorized access.”

The Commission further alleges that the companies’ deceptive and misleading representations of customer privacy protections, and their subsequent failure to notify their customers of the security breach, constitute unjust and unreasonable practices as well. Accordingly, the Commission plans to fine TerraCom and YourTel $10 million.

This is the second major enforcement action the Commission has taken to protect consumer privacy in the last two months. In September, the Commission’s Enforcement Bureau reached a $7.4 million settlement with Verizon to address the company’s unlawful marketing to two million customers without their consent or notification of their privacy rights.

More information about the Verizon settlement is here:
http://www.fcc.gov/document/verizon-pay-74m-settle-privacy-investigation

The Notice of Apparent Liability will be released at a later time and available on the FCC website.

Action by the Commission October 24, 2014, by Notice of Apparent Liability (FCC 14-173). Chairman Wheeler, Commissioners Clyburn and Rosenworcel, with Commissioners Pai and O’Rielly dissenting. Chairman Wheeler, Commissioners Clyburn, Pai and O’Rielly issuing separate
statements.

-FCC-

Related posts:

  • TerraCom notifies 150,000 Lifeline applicants after breach
  • Fraudulent signatures discovered on Lifeline phone applications – Scripps News investigation
  • Are TerraCom and YourTel the poster children for how NOT to respond to a breach?
  • IN: Telecom Company Being Investigated for Information Breach
Category: Business SectorExposureOf Note

Post navigation

← BreyerHorse.com site compromised for 18 months
Alabama Woman Sentenced to Prison for Stolen Identity Refund Fraud →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Alert: Scattered Spider has added North American airline and transportation organizations to their target list
  • Northern Light Health patients affected by security incident at Compumedics; 10 healthcare entities affected
  • Privacy commissioner reviewing reported Ontario Health atHome data breach
  • CMS warns Medicare providers of fraud scheme
  • Ex-student charged with wave of cyber attacks on Sydney uni
  • Detaining Hackers Before the Crime? Tamil Nadu’s Supreme Court Approves Preventive Custody for Cyber Offenders
  • Potential Cyberattack Scrambles Columbia University Computer Systems
  • 222,000 customer records allegedly from Manhattan Parking Group leaked
  • Breaches have consequences (sometimes) (1)
  • Kansas City Man Pleads Guilty for Hacking a Non-Profit

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Germany Wants Apple, Google to Remove DeepSeek From Their App Stores
  • Supreme Court upholds Texas law requiring age verification on porn sites
  • Justices nix Medicaid ‘right’ to choose doctor, defunding Planned Parenthood in South Carolina
  • European Commission publishes its plan to enable more effective law enforcement access to data
  • Sacred Secrets: The Biblical Case for Privacy and Data Protection
  • Microsoft’s Departing Privacy Chief Calls for Regulator Outreach
  • Nestle USA Settles Suit Over Job-Application Medical Questions

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.