LifeLock to Pay $100 Million for Bogus Ads, Bad Security

With the increasing frequency of customer-database breaches and credit-card information theft at brick-and-mortar retailers, customers have a lot of reasons to fear identity theft — and to consider identity-protection services such as LifeLock. But its users may want to rethink trusting LifeLock, as it has agreed to pay $100 million to settle charges filed in a Federal Trade Commission (FTC) complaint alleging that the company used deceptive  advertising and improperly secured customer information, including names, banking information and Social Security numbers.

An image on the LifeLock website of a credit-card swipe. Credit: LifeLock

(Image credit: An image on the LifeLock website of a credit-card swipe. Credit: LifeLock)

In an easy-to-read statement issued yesterday (Dec. 17), FTC Chairwoman Edith Ramirez explained that this settlement, the largest ever related to an FTC complaint,  stems from LifeLock's inability to provide "reasonable security for consumer data," and that the commission had found it "particularly troubling" that consumers paid for the services rendered.

The complaint, filed this past July, alleged that from 2012 to 2014, LifeLock violated the terms of a 2010 court-ordered agreement and resulting settlement that forbade LifeLock from engaging in further deceptive advertising and mandated that it beef up its data-security practices. 

MORE: The Best (and Worst) Identity Theft Protection

The FTC also found fault in LifeLock's claims that it protects "consumers' sensitive data with the same high-level safeguards used by financial institutions" and that the company "would send alerts 'as soon as' it received any indication that a consumer may be a victim of identity theft."

As a further penalty, going forward, the FTC will extend the terms of the 2010 agreement, which now subjects LifeLock to regular monitoring and audits until 2023.

In 2010, the FTC alleged that LifeLock had not been encrypting customer information, nor had created any security measures to limit employee access to those customer records. In the subsequent settlement, LifeLock agreed to pay $12 million for engaging in deceptive advertising. The record penalty LifeLock agreed to yesterday is meant to be proportional to its recent earnings; LifeLock's end-of-year financial report for 2014 revealed the company had revenues of $476 million, a substantial increase from the $370 million it earned in 2013.

"Our settlement, which provides for substantial consumer redress, is an important step in ensuring that LifeLock complies with its continuing obligations to engage in truthful advertising and protect the security of its customers’ information," the FTC said in a formal statement.

Commissioner Maureen K. Ohlhausen dissented from the FTC order, citing lack of "clear and convincing evidence that LifeLock failed to establish and maintain a comprehensive information security program."

Ohlhausen noted that LifeLock had fully complied with the Payment Card Industry Data Security Standard (PCI-DSS), the widely used standard for online credit-card processing. The other three commissioners stated that PCI-DSS was not enough to satisfy the terms of the 2010 agreement; PCI compliance would have had no bearing on the charges of deceptive advertising.

In its own statement released yesterday, LifeLock admitted the FTC's charges, but said its former bad behavior had ended, explaining that the "the settlement does not require us to change any of our current products or practices."

According to the FTC, $68 million of the settlement may be used to recompense LifeLock customers who have filed several class-action suits against the company. Monies distributed from that fund "must be paid directly to and received by customers" and not used to pay legal or administrative fees. (Legal fees in lawsuits are normally one-third of award amounts.)

Earlier this year, Tom's Guide gave LifeLock an Editor's Choice award in a review roundup of identity-protection services. We will be re-evaluating that award.

TOPICS
Henry T. Casey
Managing Editor (Entertainment, Streaming)

Henry is a managing editor at Tom’s Guide covering streaming media, laptops and all things Apple, reviewing devices and services for the past seven years. Prior to joining Tom's Guide, he reviewed software and hardware for TechRadar Pro, and interviewed artists for Patek Philippe International Magazine. He's also covered the wild world of professional wrestling for Cageside Seats, interviewing athletes and other industry veterans.

Latest in Online Security
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Latest in News
Maria Debska in "Just One Look" now streaming on Netflix
3 best Netflix shows in March you haven't watched yet
Wolfenstein: The Old Blood
Amazon is giving away a ton of free games for its Big Spring Sale — here’s how to claim yours
A TV with the Netflix logo sits behind a hand holding a remote
Netflix is rolling out a big video quality upgrade — what you need to know
Choi Hyun-Wook, Hong Kyung, and Park Ji-hoon in "Weak Hero Class 1" now streaming on Netflix
This action-packed K-drama is now streaming on Netflix — and now’s the time to binge-watch before season 2
OnePlus 13 back, leaning against blue wall
OnePlus 13T could come with an even bigger battery than OnePlus 13 — this is incredible
Apple Watch Ultra 2
Apple Watch Ultra 3 just tipped for two major upgrades