LifeLock Inc. agreed to pay $100 million to resolve findings that it had violated a 2010 consent order by continuing to misrepresent the extent to which its identity theft protection service actually protected members from identity theft — making claims about its monitoring capabilities and protection benefits that went beyond what its actual service could deliver and that had been specifically addressed in the earlier order, resulting in one of the largest penalty amounts ever assessed for violation of an existing consent order.DOCUMENTED
LifeLock's marketing built its brand on aggressive claims about its ability to protect members' identities — claims featuring specific representations about the comprehensiveness of its monitoring, the speed of its alerts, and the protection it provided against unauthorized use of members' personal information. The company's original 2010 consent order followed findings that many of those claims were not supported by what the service actually did, and required LifeLock to stop making unsupported protection claims. The subsequent finding that LifeLock had continued to make such claims despite the earlier order was what drove the dramatically elevated penalty amount.DOCUMENTED
- LifeLock's 2010 consent order required it to stop misrepresenting its identity protection services and to implement reasonable data security
- Regulators found that LifeLock continued making unsupported protection claims after the 2010 order took effect
- LifeLock failed to adequately secure members' personal data despite the 2010 order's data security requirements
- The service did not monitor all three credit bureaus as advertised, leaving gaps in the monitoring it had marketed as comprehensive
- $100 million settlement — the largest penalty ever assessed for violation of a prior consent order at the time it was announced
The Original Order and Its Violations
The 2010 consent order that LifeLock violated had required it to stop making false claims — including the claim that its service provided comprehensive monitoring that would prevent identity theft — and to implement a comprehensive security program protecting members' personal information. The monitoring claims were problematic because LifeLock's actual monitoring capability at the time covered only certain categories of identity theft indicators and did not provide the comprehensive coverage implied by its advertising. The data security requirement reflected the irony of an identity protection company that held large amounts of sensitive personal information without adequate security to protect it.DOCUMENTED
The subsequent $100 million action found that LifeLock had continued, after the 2010 order, to make claims about its protection and monitoring capabilities that were not supported by what the service actually provided. The monitoring did not cover all three credit bureaus despite advertising that implied comprehensive credit monitoring. Alerts were not as timely as advertised. And the data security practices that the 2010 order required had not been implemented to the standard the order required, leaving member data exposed to the same risks the order was supposed to address.DOCUMENTED
The Irony of an Insecure Identity Protection Service
The data security finding in the LifeLock case is particularly striking in context: a company that markets itself specifically on the premise of protecting consumers from identity theft and the misuse of their personal information was found to have inadequately secured the personal information it held for its own members. LifeLock held members' Social Security numbers, financial account information, and other highly sensitive personal data — the exact information that identity theft protection services exist to safeguard — and did not maintain adequate security for those records despite a prior consent order specifically requiring it to do so.DOCUMENTED
The data security failure is not merely ironic — it is a substantive harm. Members who paid LifeLock for identity theft protection and provided sensitive personal information in the process were exposed to the risk of having that information compromised through the very service they had purchased for protection. This harm is separate from whether the protection claims were accurate — a consumer who is misled about protection capabilities and also has their data inadequately secured has experienced a compound failure from the service they paid to protect them.REVIEWED
LifeLock — a company whose entire value proposition was protecting members' identities — was found to have inadequately secured those members' Social Security numbers and financial account information, exposing to breach the precise data the service was supposed to safeguard.
What Identity Protection Services Can and Cannot Do
Identity protection services provide real benefits — credit monitoring alerts, dark web monitoring for compromised credentials, Social Security number monitoring, and assistance with resolving identity theft incidents can all reduce the harm consumers suffer from identity theft. What they cannot do is prevent identity theft in all its forms, and their marketing should not imply they can. Consumers evaluating identity protection services should look for specific descriptions of what the service monitors, how quickly alerts are generated, which credit bureaus are included in credit monitoring, and what assistance is provided in the event of an identity theft incident rather than for marketing language implying comprehensive protection. The FTC maintains a free identity theft resource at identitytheft.gov that provides guidance on recovering from identity theft without requiring a paid subscription service.REVIEWED
Free Identity Monitoring Resources
Consumers who want to monitor their credit and identity without paying for a commercial service have access to several free resources that cover many of the same functions that paid services offer. AnnualCreditReport.com provides free access to your credit reports from all three major bureaus — currently available weekly — allowing you to review your credit file for unauthorized accounts, inquiries, or other signs of identity theft. Placing a free credit freeze at all three bureaus (Equifax, Experian, and TransUnion) is the most effective single action a consumer can take to prevent new account fraud using their identity, and is available at no cost under federal law. IdentityTheft.gov, the FTC's identity theft response resource, provides step-by-step guidance and personalized recovery plans for consumers who discover their identity has been compromised. Many financial institutions also offer free credit monitoring and dark web alert services to account holders that provide additional layers of monitoring without a subscription fee. Paid identity protection services may add value through insurance coverage and recovery assistance, but the free resources cover the monitoring functions that most consumers rely on those services for.
Sources behind this report
Have documents relevant to this story? Reach us through our tips channel.