DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

FCC jumps into data security; plans $10 million fine for carriers that breached consumer privacy

Posted on October 24, 2014 by Dissent

Back in 2013, I blogged about a breach involving TerraCom and YourTel. Their breach response was so poor that I devoted two posts to criticizing them. But as bad as the breach and their response were, things got even worse when Scripps News kept investigating and uncovered more problems. It was no surprise, therefore, to learn that the Indiana Attorney General was investigating.

What is a surprise, however, is an announcement today by FCC that they intend to fine TerraCom and YourTel $10 million:

This is an unofficial announcement of Commission action. Release of the full text of a Commission order constitutes official action.

See MCI v. FCC. 515 F 2d 385 (D.C. Cir. 1974).

FCC PLANS $10 MILLION FINE FOR CARRIERS THAT BREACHED CONSUMER PRIVACY

TerraCom and YourTel Allegedly Stored Customers’ Personal Information Online in a Format Accessible Through Routine Internet Search

Washington, D.C. – The FCC intends to fine TerraCom, Inc. and YourTel America, Inc. $10 million for several violations of laws protecting the privacy of phone customers’ personal information. According to an investigation by the Enforcement Bureau, TerraCom and YourTel apparently stored Social Security numbers, names, addresses, driver’s licenses, and other sensitive information belonging to their customers on unprotected Internet servers that anyone in the world could access. The information was gathered to demonstrate eligibility for the Lifeline program, which is a Universal Service Fund program that provides discounted phone services for low-income consumers. The companies allegedly breached the personal data of up to 305,000 consumers through their lax data security practices and exposed those consumers to identity theft and fraud. This is the Commission’s first data security case and the largest privacy action in the Commission’s history.

“Consumers trust that when phone companies ask for their Social Security number, driver’s license, and other personal information, these companies will not put that information on the Internet or otherwise expose it to the world,” said Travis LeBlanc, Chief of the FCC’s Enforcement Bureau. “When carriers break that trust, the Commission will take action to ensure that they are held accountable for unjust and unreasonable data security practices.”

In their privacy policies, the two companies stated that they had in place “technology and security features to safeguard the privacy of your customer specific information from unauthorized access or improper use.” Yet, from September 2012 through April 2013, the sensitive documents they collected from consumers were apparently stored in a format accessible via the Internet and readable by anyone. Ultimately, the personal information of up to 305,000 low-income consumers was apparently exposed to public view. Yet even after the companies learned of this security breach, they allegedly failed to notify all potentially affected consumers, depriving them of any opportunity to take steps to protect their personal information from misuse by Internet thieves.

The Commission alleges that the carriers’ failure to reasonably secure their customers’ personal information violates the companies’ statutory duty under the Communications Act to protect that information, and also constitutes an unjust and unreasonable practice in violation of the Act, given that their data security practices lacked “even the most basic and readily available technologies and security features and thus creates an unreasonable risk of unauthorized access.”

The Commission further alleges that the companies’ deceptive and misleading representations of customer privacy protections, and their subsequent failure to notify their customers of the security breach, constitute unjust and unreasonable practices as well. Accordingly, the Commission plans to fine TerraCom and YourTel $10 million.

This is the second major enforcement action the Commission has taken to protect consumer privacy in the last two months. In September, the Commission’s Enforcement Bureau reached a $7.4 million settlement with Verizon to address the company’s unlawful marketing to two million customers without their consent or notification of their privacy rights.

More information about the Verizon settlement is here:
http://www.fcc.gov/document/verizon-pay-74m-settle-privacy-investigation

The Notice of Apparent Liability will be released at a later time and available on the FCC website.

Action by the Commission October 24, 2014, by Notice of Apparent Liability (FCC 14-173). Chairman Wheeler, Commissioners Clyburn and Rosenworcel, with Commissioners Pai and O’Rielly dissenting. Chairman Wheeler, Commissioners Clyburn, Pai and O’Rielly issuing separate
statements.

-FCC-

Category: Business SectorExposureOf Note

Post navigation

← BreyerHorse.com site compromised for 18 months
Alabama Woman Sentenced to Prison for Stolen Identity Refund Fraud →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Alabama Man Sentenced to 14 Months in Connection with Securities and Exchange Commission X Hack that Spiked Bitcoin Prices
  • Japan enacts new Active Cyberdefense Law allowing for offensive cyber operations
  • Breachforums Boss “Pompompurin” to Pay $700k in Healthcare Breach
  • HHS Office for Civil Rights Settles HIPAA Cybersecurity Investigation with Vision Upright MRI
  • Additional 12 Defendants Charged in RICO Conspiracy for over $263 Million Cryptocurrency Thefts, Money Laundering, Home Break-Ins
  • RIBridges firewall worked. But forensic report says hundreds of alarms went unnoticed by Deloitte.
  • Chinese Hackers Hit Drone Sector in Supply Chain Attacks
  • Coinbase says hackers bribed staff to steal customer data and are demanding $20 million ransom
  • $28 million in Texas’ cybersecurity funding for schools left unspent
  • Cybersecurity incident at Central Point School District 6

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Privacy enforcement under Andrew Ferguson’s FTC
  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law
  • CFPB Quietly Kills Rule to Shield Americans From Data Brokers
  • South Korea fines Temu for data protection violations
  • The BR Privacy & Security Download: May 2025
  • License Plate Reader Company Flock Is Building a Massive People Lookup Tool, Leak Shows
  • FTC dismisses privacy concerns in Google breakup

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.