DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Office Depot and Tech Support Firm Will Pay $35 Million to Settle FTC Allegations That They Tricked Consumers into Buying Costly Computer Repair Services

Posted on March 29, 2019 by Dissent

Office Depot, Inc. and a California-based tech support software provider have agreed to pay a total of $35 million to settle Federal Trade Commission allegations that the companies tricked customers into buying millions of dollars’ worth of computer repair and technical services by deceptively claiming their software had found malware symptoms on the customers’ computers.

Office Depot has agreed to pay $25 million while its software supplier, Support.com, Inc., has agreed to pay $10 million as part of their settlements with the FTC. The FTC intends to use these funds to provide refunds to consumers.

“Consumers have a hard enough time protecting their computers from malware, viruses, and other threats,” said FTC Chairman Joe Simons. “This case should send a strong message to companies that they will face stiff consequences if they use deception to trick consumers into buying costly services they may not need.”

In its complaint, the FTC alleges that Support.com worked with Office Depot for nearly a decade to sell technical support services at its stores. Office Depot and Support.com used PC Health Check, a software program, as a sales tool to convince consumers to purchase tech repair services from Office Depot and OfficeMax, Inc., which merged in 2013.

The Office Depot companies marketed the program as a free “PC check-up” or tune-up service to help improve a computer’s performance and scan for viruses and other security threats. Support.com, which received tens of millions of dollars in revenue from Office Depot, remotely performed the tech repair services once consumers made the purchase.

The FTC alleges that while Office Depot claimed the program detected malware symptoms on consumers’ computers, the actual results presented to consumers were based entirely on whether consumers answered “yes” to four questions they were asked at the beginning of the PC Health Check program. These included questions about whether the computer ran slow, received virus warnings, crashed often, or displayed pop-up ads or other problems that prevented the user from browsing the Internet.

The complaint alleges that Office Depot and Support.com configured the PC Health Check Program to report that the scan found malware symptoms or infections whenever consumers answered yes to at least one of these four questions, despite the fact that the scan had no connection to the “malware symptoms” results. After displaying the results of the scan, the program also displayed a “view recommendation” button with a detailed description of the tech services consumers were encouraged to purchase—services that could cost hundreds of dollars—to fix the problems.

The FTC alleges that both Office Depot and Support.com have been aware of concerns and complaints about the PC Health Check program since at least 2012. For example, one OfficeMax employee complained to corporate management in 2012, saying “I cannot justify lying to a customer or being TRICKED into lying to them for our store to make a few extra dollars.” Despite this and other internal warnings, Office Depot continued until late 2016 to advertise and use the PC Health Check program and pushed its store managers and employees to generate sales from the program, according to the complaint.

The Commission alleges that both companies violated the FTC Act’s prohibition against deceptive practices.

In addition to the monetary payment, the proposed settlement also prohibits Office Depot from making misrepresentations about the security or performance of a consumer’s electronic device and requires the company to ensure its existing and future software providers do not engage in such conduct. As part of its proposed settlement, Support.com cannot make, or provide others with the means to make, misrepresentations about the performance or detection of security issues on consumer electronic devices.

The Commission vote authorizing the staff to file the complaint and stipulated final orders was 5-0. The FTC filed the complaint and stipulated final orders in the U.S. District Court for the Southern District of Florida.

Source: FTC


Related:

  • Some lower-tier ransomware gangs have formed a new RaaS alliance -- or have they? (1)
  • Another plastic surgery practice fell prey to a cyberattack that acquired patient photos and info
  • How a hacking gang held Italy’s political elites to ransom
  • Uncovering Qilin attack methods exposed through multiple cases
  • Predatory Sparrow Strikes: Coordinated Cyberattacks Seek to Cripple Iran's Critical Infrastructure
  • Ex-CISA head thinks AI might fix code so fast we won't need security teams
Category: Business SectorCommentaries and AnalysesOf Note

Post navigation

← OCR Acting Deputy Director Talks Risk Management at Advocacy Summit
24K Cremation Society of Pa. customers notified of possible loss of personal information →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Suspected Russian hacker reportedly detained in Thailand, faces possible US extradition
  • Did you hear the one about the ransom victim who made a ransom installment payment after they were told that it wouldn’t be accepted?
  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.