October 12, 2006 4:00 AM PDT

Class action suit over ID theft tossed out

A federal judge in Arkansas has thrown out a class action lawsuit against Acxiom, which exposed massive amounts of Americans' personal information in a high-profile Internet security snafu three years ago.

Even though a spammer had downloaded more than one billion records from the company, U.S. District Judge William Wilson ruled that there was no evidence that Acxiom's purloined database had been used to send junk e-mail or postal mail.

Because the class action attorneys could not prove that anyone's information had actually been misused, Wilson dismissed the case and the request for damages on the grounds that any harm would be entirely speculative. "Because plaintiff has not alleged that she has suffered any concrete damages, she does not have standing under the case-or-controversy requirement," he wrote.

The decision (PDF), published on Oct. 3, could prove influential in other identity fraud cases where breaches have exposed personal information such as home addresses and Social Security numbers, but there's no proof that the information has been misused.

"If this case is not the first, it's certainly one of the first to deal with these issues," said David Kramer, a partner at the law firm of Wilson Sonsini Goodrich & Rosati, who represents Acxiom.

It's not entirely clear what information was downloaded from Acxiom, except that it was information owned by one of its customers rather than information Acxiom collected itself. Acxiom's business includes providing databases for direct marketers, including InfoBase, described by the company as "the largest collection of U.S. consumer and telephone data in one source," and Personicx, which features the "specific consumer and demographic characteristics" of tens of millions of American households. Acxiom also provides information to law enforcement agencies, and once counted former presidential candidate Wesley Clark as a board member.

In a related case dealing only with the rules governing federal agencies, the U.S. Supreme Court ruled in 2004 that someone who had his Social Security number disclosed by the Department of Labor--but experienced no actual harm such as identity fraud--was not entitled to damages (PDF).

The class action lawsuit arose out of a security breach at Acxiom in 2003 in which the company allegedly did not adequately protect a server used for file transfers (FTP). Earlier this year, Scott Levine was sentenced to eight years in prison after a federal jury convicted him of 120 counts of unauthorized access to Acxiom's computers.

Levine is a native of Boca Raton, Fla. and former chief executive of a bulk e-mail company called Snipermail.com, which had been dubbed a spammer by the Spamhaus Project. But federal prosecutors said there was no evidence that Levine used the downloaded data for identity fraud.

According to court documents, Levine and others broke into an Acxiom server used for file transfers and downloaded an encrypted password file called "ftpsam.txt" in early 2003. Then they ran a cracking utility on the ftpsam.txt file, prosecutors said, discovered 40 percent of the passwords, and used those accounts to download even more sensitive information.

The revelations raised eyebrows, in part because Acxiom Chairman Charles Morgan had offered public assurances about the company's security, including in testimony (click here for PDF) to the Federal Trade Commission. Morgan said that his company takes "exceptional security measures to protect the information we maintain for our own information products...to ensure that information will not be made available to any unauthorized person."

No decision about an appeal
An attorney who is co-counsel on the lawsuit against Acxiom said on Wednesday that the plaintiffs have not yet decided whether to appeal. "We're going to consider what our potential avenues are over the coming week or so, and then make a decision," said Scott Poynter of the firm Emerson Poynter in Little Rock, Ark.

Emerson Poynter describes itself as a firm that has "specialized in class action litigation for over 15 years" and says all of those cases are handled on a contingency-fee basis. It has filed class-action lawsuits against companies including AOL Time Warner, Nortel Networks and Coca-Cola, typically alleging securities fraud. It has indicated it will target companies that are accused of stock option backdating as well.

"Our client tried to find out from Acxiom if her information was compromised, and they wouldn't tell her," Poynter said. "We think the consumers that have their private information stored by a company should have that right...But maybe the law needs to catch up with the Internet and the way people's privacy is being invaded today."

In the lawsuit that Emerson Poynter and a second law firm filed against Acxiom in April, they raised two vague arguments: That the data-broker was negligent, and that its actions "caused an unreasonable intrusion on the privacy" of people whose records were exposed. Those legal claims require someone to have suffered actual harm beyond a possibly increased risk of identity theft, Judge Wilson concluded. (The lawyers asked for "compensatory and punitive damages" and attorneys' fees of an unspecified amount.)

"This may lead attorneys looking to bring these sorts of claims to ensure their clients have suffered actual harm rather than speculative injury before filing suit," said Kramer, Acxiom's attorney.

But Chris Hoofnagle, a senior fellow at the University of California at Berkeley's law school who has been critical of Acxiom, thinks that the outcome might have been different if the attorneys had filed the suit in California. State law (AB1950) requires businesses that own or license personal information about Californians to "implement and maintain reasonable security procedures," Hoofnagle noted, though that law was not in place at the time of the Acxiom incident.

"I would hope that one could think of more causes of action other than identity theft and negligence," Hoofnagle said.

Levine's was not the first prosecution to stem from the security practices on Acxiom's FTP server. An Ohio man named Daniel Baas previously pleaded guilty to illegally entering Acxiom's FTP site. That investigation led federal police--including the FBI and Secret Service--to Levine, according to the Justice Department.

See more CNET content tagged:
Acxiom Corp., class action, identity fraud, class action lawsuit, identity theft

Add a Comment (Log in or register) 4 comments
Another Abdication of Responsibility
by Big Tsunami October 12, 2006 8:00 AM PDT
Until the time comes when the compromise of data security and abuse of personal information is catastrophic, will US legislators do anything to protect the digital rights of consumers. Consumers need a DRM that says every sharing is an 'opt in' situation. That is, they must tell you and you have to give explicit permission before your personal information is shared with others or that the information repository is accessible from other countries or resident there.

Until we stop allowing this foolishness to proliferate, we are steps closer to a catastrophic compromise.
Reply to this comment View reply
Ludicrous at best
by wbenton October 15, 2006 7:40 AM PDT
So if I knock over Fort Knox and there is no traces of me using the Gold from there... because I've hidden it in a valut for the next 20 years... I can get away with the theft?

Same thing... different circumstances.

The judge has just passed that it's ok to hack databases if it can't be proved that the data was used malaciously. Even though it can be proven that it was stolen.

A definate backward step in internet history!!!

FWIW
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • Nanotech: The Circuits Blog

    Timing rumors surface for AMD plant spin-off

    Rumors persist that Advanced Micro Devices is planning to spin off all or part of its manufacturing operations.

  • Gallery

    Photos: Ron Paul's RNC alternative

    As the Republican convention took place just miles away, a crowd rallied for the former presidential candidate and his message of limited government, ensured civil liberties, lower taxes, and peace.

  • Digital Noise: Music and Tech

    Was 1980s music that bad?

    NPR asks listeners which year featured the best music, and the 1980s emerge as a bleak era. Personally, the '80s figure prominently in my collection, but well behind the 1970s.

  • Beyond Binary

    Microsoft begins big ad push

    Microsoft's multi-year push, estimated at $300 million, begins with a spot featuring Bill Gates and Jerry Seinfeld aired during Thursday's NFL game.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Digital Media

    Michael Moore plans Net-only film premiere

    Filmmaker plans to premiere his latest documentary exclusively on the Internet for free, forgoing the traditional theatrical release.

  • Video

    Political party playlists

    We know the Democrats and Republicans are split over policy issues, but does their musical taste fall down party lines too? And what kind of gadgets did they bring to the conventions to listen to their music? CNET reporter Kara Tsuboi finds out.

  • News - Politics and Law

    What you can--and can't--find about Palin on the Internet

    John McCain's choice of Sarah Palin as a running mate has inspired a wealth of creativity on the Internet.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Photos: The brains behind Google Chrome

    Here's a look at some of the engineers and executives who took the stage at the company's headquarters as they unveiled the new browser.

  • Crossfade

    Ying Yang Twins, 'Look Back At It': Free MP3 of the Day

    This amped-up duo gets the party started with a mix of crisp, Southern hip-hop beats and shout-along rhymes. Download a free MP3 of "Look Back At It" courtesy of CNET Download Music.

  • Green Tech

    Clean-tech group forms to support Obama

    "Clean Tech and Green Business for Obama" aims to raise $1 million for the Democratic presidential nominee while elevating issues of climate change and alternative energy.