Byron Bay data breach victim told to pay Adidas, NBA $1.2M by US courts
abc.net.au
abc.net.au
Somehow banks have re-named it from "bank fraud" to "identity theft," deftly shifting responsibility onto some unrelated third party, who now has to deal with it. "Your identity was stolen! That makes you the victim. Now go help fix it!"
Banks should not be able to shift the blame. They did a crappy job and lent money or opened an account for someone they shouldn't have. They are the ones who should bear the burden of mopping up their mistake.
In Norway you can voluntarily register as not wanting to allow credit assessments to be performed on you.
This in turn can help a bit because it results in most attempts at making loans in your name not being possible.
https://www.datatilsynet.no/regelverk-og-verktoy/sporsmal-sv...
There are four companies in Norway that do credit assessments. You have to individually register your desire to not allow credit assessments for your name with all four of these.
https://tfinans.no/blogg/frivillig-kredittsperre
But then, what protects you against someone simply requesting that your credit is unlocked and then taking loans in your name after all? Well, from what I gather one would have to use BankID to confirm that credit is to be unlocked.
So even if someone steals my passport, they will not immediately be able to unlock my credit. They’d have to jump through a bunch of hoops to also steal my BankID.
https://consumer.ftc.gov/articles/what-know-about-credit-fre...
I (and millions of other people) learned how to do a credit freeze after having our personal info leaked in the Equifax data breach of 2017:
https://en.wikipedia.org/wiki/2017_Equifax_data_breach
Having that credit freeze saved me from at least two attempted frauds since then - I was notified by two credit card issuers that credit card applications in my name that I had never made were rejected because my credit file was frozen.
I'm dreading trying to recall the PINs I used when the time comes to un-freeze them.
Still glad I did it, though. However burdensome the PIN recovery process will be, I'm sure it's less stress than dealing with fraud.
The "locked" state should be the default, whatever extra checks they need to do to a person that has it "frozen", that should just be the default to start any credit!
If anyone has some dire need for easy credit all the time they can do the opposite and go to some "light checks" state like TSA pre-check.
Brings to mind the tale that jaywalking laws were the creation of early-days automobile manufacturers and dealers who wanted to clear the streets for the vehicles they wanted to sell. [0]
[0] https://www.vox.com/2015/1/15/7551873/jaywalking-history
The argument would be that If there is not a single slip of evidence tying you physically to the money Except your PII Then the banks anti-money laundering should have catched it. That gets their attention right away since the fines in that cases are proper billions.
If they don’t settle, you go for the kill and settle that PII is not uniquely tied to legal intent (heck, it wasn’t you! The intent is missing and that’s what you point out as well.)
The problem is that that case will take you 7+ years, all the way to the various supreme courts (local, European). It’s why Max Schrems is a hero, except banks are worse adversaries than government regulators.
This whole digital world has had some impact on our two thousand years plus of contract law. It’s sad judges don’t go back to the basics in these cases. Show me the contract (into the abyss).
This works for me.
This is true to a large extent but having worked in resolving "identity theft" I can say that it is complex.
In a place like the UK the requirements for a bank loan are pretty stringent but here in Australia they are much much lower and people hate friction. Authentication is a hard problem. Knowing someone's creditworthiness is a hard problem. There are a also many of people out there who are willing to claim "identity theft" has occurred to mean that it is complicated.
Most of the time for people whose identities had been stolen it was fairly easy to remove based on the most cursory evidence (which often I only had access to because I had access to air gapped data that was kept for far longer than the 7 years it was meant to be kept).
The status quo exists because it inconveniences just few enough people and is an acceptable amount of risk to the powerful. One side of politics will denounce anything that looks after the interest of both these groups as too much "red tape" and the other will denounce it as "discriminatory".
For comparison I look to the family violence measures we introduced here in the last decade. It was a battle which took years of firmly but politely refuting the opposing ideas "family violence victims should never have to justify themselves to a credit provider" against "credit providers should never increase their risk without having charged more up front".
A compromise model was found where the credit providers effectively pay for the losses but in reality they just charge it back to their customers. Right now paying for identity theft is a lottery. In future it's going to be internalised up front. This will be good for the victims but for the rest of us its an increased cost.
I don’t doubt her story, but if you can claim the account is yours when it suits you (“where’s my stuff?!”) is it fine to claim it’s not yours when it doesn’t (“these transactions were done by someone else!”)?
Is there a contradiction there? Perhaps not: I doubt you can use a PayPal database row to enforce a contract — you’d need an invoice or order confirmation — so neither should another party be able to use the PayPal db to convict you of fraud.
Was there other evidence against Luke?
It is insane to me that PayPal, Venmo, VISA, etc, all can allow someone who isn't him to open accounts, run transactions, etc, but not have to bear the legal liability of it, and instead it appears to be him that is legally liable.
IMO, the transacting companies here are the ones that need to be charged. I never consented into the American credit system, yet by virtue of being born here, all these companies can, and will, apparently let others open accounts in my name, with no liability.
Are there statistics on this somewhere?
"very common" has no standard meaning, so the statement is meaningless either way.
I can’t find anything stating this is “very common”. I guess as a rough metric for “very common” let’s say on a similar level to heart attacks. Quite rare still but common enough that you could be justified in calling it very common.
So 850,000 cases per year.
I would start with the number of civil cases brought against police officers that are thrown out due to qualified immunity.
https://eji.org/issues/qualified-immunity/
https://www.naacpldf.org/qualified-immunity-myths-and-danger...
Or number of police departments with civilian oversight boards though many of these are proven to be ineffective.
https://portal.cops.usdoj.gov/resourcecenter/ric/Publication...
Or maybe I'm too sheltered living in my gated community or whatever, and this is actually "very common" in the usual colloquial definition. Feel free to prove me wrong.
[1] https://www.washingtonpost.com/graphics/investigations/polic...
A quick look at my county jail roster shows that a lot of the drug cases - but not all - are of that sort.
Areas with more overall crime are going to have more police officers patrolling as well.
Of course, it’s probably a bit of A, B, and C.
Instead, it has been widely documented that they freqently flaunt programs intended to provide oversight, almost never are successfully prosecuted or punished, and commit homicides with regularity.
I think one way is to note that this post was about being inaccurately charged with a felony - not about cops. The request for stats was not “cop stats” but identity fraud based felony and as a result arrest at routine traffic stop.
If a cop sees you have multiple felonies in another state, it’s quite literally their job to arrest you. Do you suggest they see someone charged with multiple felonies and just say have a good day?
No, the post was about being charged inaccurately due to identity theft. Perhaps you are overly eager to criticize police and became uninformed with reading the comment thread.
It's just so frustrating and deflating to go through the process. It's a chore that shouldn't really be our problem - but it is and it feels terrible to be beholden to that process and ultimately come out losing in the end when you get a letter like that in the mail.
I had a identity theft come up a few years ago and I'm still dealing with it (all the way back from 2016!). But at the end of the day, I really shouldn't complain because things could always have been worse.
I just empathize with your final sentiment completely. We're just...beholden to it. Bleh.
In a 6 month period I had; - My private health insurance data leaked (AHM/Medibank) - including claim history, medicare number, password, username, email, phone - My old phone account (Optus) - including my phone number, my current passport number(!!!), current address, phone. - My old credit card account (Latitude finance) - including my current passport, driver license, my income history and bank statements that was provided to get the credit card originally, address, phone, email
The ONLY thing that any of these businesses have done is pay for a replacement passport and a 12 month credit watch. Optus wasn't even a 'breech', they had an API exposed with the all the data!
How is someone meant to protect themselves from this? It is pure negligence. Until governments legislate that the punishment for exposing personal data is more expensive than the work and infrastructure required to keep it secure this will continue to happen.
The EU did. Everyone, for some inexplicable reason hates it; and not the casual hate one spews when it rains or traffic is bad but a deep visceral hatred normally reserved for war criminals or kiddie fiddlers.
Otherwise the court should just throw this out. It’s only 1.2m.
Hopefully, the judgement will be dismissed since it’s based on identity fraud.
Who in their right mind would insure Adidas (or any other internationally famous brand) for trademark infringement? You're almost guaranteed to pay out millions in "damages" per year.
I remember many years ago, the startup I worked for was required to have insurance as part of our funding round and it covered stuff like officers freaking out in public and all sorts of odd things I didn’t think was insurable.
Corporate insurance is pretty interesting in this regard.
And no matter who is insuring, in the US it’s probably reinsured by Marsh McClellan [1], a huge reinsurance firm.
(Of course I am being slightly hyperbolic here; deal with it.)
Despite the bigger risks/penalties involved with being unlicensed (driver and/or vehicle) and uninsured, it does seem that these at-risk drivers are less safe. Uninsured driver premiums are explicitly bundled. Accidents lead to worse physical outcomes for at-risk drivers (https://www.sciencedirect.com/science/article/pii/S259019822...)
This would correlate with your outlook.
Apparently a Trump-appointed judge in Miami is what is happening. Out of our hands unfortunately.
I would be sad if that skillset had been lost.
Way back then we would send RSA tokens to the top users to stop them from getting hacked, but since they cost $10 each and required training and setup with an agent, only top users would get them.
Part of this is of course genuine security verifications but a lot of it is due to RSA Security's obtuse design decisions. We tend to avoid them entirely and instead rely on modern SAML providers with app-based 2FA whenever we can now.
I don't get it, based on this[1] it looks like electronic service is only possible if the party consented. That seems fairly reasonable. How would this have happened? Is there more to this?
The docket for this case is here: https://www.courtlistener.com/docket/66634655/adidas-ag-v-th.... I'd be very interested to see what the "Certificate of Service" contains, but I don't have PACER access.
https://servingnotice.com/Da29d1x/index.html
Apparently "Serving Notice dot com" is sufficient to say someone has been served?
I downloaded the Pacer documents with Recap enabled so you should be able to see them on the CourtListener website.
Apparently, because the judge allowed it. Looking at the relevant document[1], the reason that was allowed was that:
1. the defendant is foreign
2. "the defendants conducted their businesses over the Internet"
3. "the defendants used e-mail regularly in their businesses"
4. "the plaintiff shows e-mail is likely to reach defendants"
[1] https://servingnotice.com/Da29d1x/015%20-%20221221%20[_]%20O...
JFC
Contract signings, online court service, title changes, etc should not be valid without an offline record examiner who affirms under threat of perjury that the parties involved are who they claim (or are claimed to be).
The existing system isn't foolproof but, by and large, it works perfectly well. If the transactions in TFA truly were fraudulent, no court is going to hold her liable. The bigger problem here is a US court being happy to issue ex parte judgments for someone who should have been trivially contactable.
I just tried to set up an eBay account to buy an exhaust part. I created the account, sent the seller a message and twenty minutes later, I got a notification from eBay that I (and anyone from my household) was permanently banned because I was a "threat to the eBay community".
I haven't been on eBay for ages, and as far as I know, was certainly never threatening to anyone on or off eBay. Nobody at eBay would tell me what had gone wrong -- in fact, as soon as I asked what the problem was, they said that they had to "end the call now".
Maybe if I had signed up in person, they could let me know what crimes I'm supposed to have committed or at least save me a hour by not allowing the signup in the first place.
I’m moving away and selling some of our stuff that we can’t take with us. I have a spare 5G/LTE router that I thought I’d throw up on eBay as well as Facebook Marketplace.
I followed their onboarding process to the letter to create a listing, verify my email and mobile phone, add a bank account, etc.
About an hour later I got an email saying I’ve been “permanently suspended because of activity that we believe was putting the eBay community at risk”.
Apparently doing nothing but following their onboarding process is putting the community at risk. They also tell you that “this decision (that was made 100% by an automated system) was not made lightly”.
Get fucked, eBay.
Somehow this hasn't stopped the people selling empty PS5 boxes and knockoff handbags at all.
Was it a catalytic converter?
Is eBay salty about catalytic converters?
I do, if the service involves hard identity/finance. Maybe where I'm from is odd, but you can't go into a neighborhood without tripping over a notary, there are mobile notaries, notaries in every white collar office etc. Not too inconvenient for a one time (per major action) event.
That's a very good idea.
You're not using those words correctly.
If that would allow me to 100% regain control of a hacked account. The answer is yes.
You're saying like it's bad. It's not. In fact, it's wonderful.
Yes.
In Denmark we have a thing called “MitID” (MyID) which is basically a government login and which you can use to sign and also login to all kinds of things that need to confirm your identity (e.g. Phone subscription, taxes, 3DS verification for Credit Card transactions, etc).
It’s essentially 2FA, works by the site sending a confirmation to an app on your phone that is behind PIN code. The analog version is a paper slip with 100 lookup codes.
National ID systems are such nonsense it is appalling there are people stupid enough to think this is a Good Thing.
Easy is NOT always better. The best things in life are definitely not free.
You would have to steal a username + phone + PIN code for phone + PIN code for MitID app.
If that happens, then it would also be trivial to unlink the app from that phone.
At no point in time would you be unaware of the theft here.
Contrast this to what happens in the US often: your personal info is leaked from the plethora of places it’s kept. Someone can now in perpetuity exploit your identity, or at the very least for a long time until you find out randomly.
Which system sounds better to you? I sure know that I’d prefer the first one.
I’d welcome any actual arguments against it, but you’ve not really presented any at all so far.
And when your phone is hacked then all three are up for grabs?
"Contrast this to what happens in the US often: your personal info is leaked from the plethora of places it’s kept."
And yes, totally never is your govt info leaked from the plethora of places it is kept. /s
The problem is not having govt information, the problem is having it kept on phones or entered on devices at all.
"I’d welcome any actual arguments against it,"
See the above. I dislike the automated exfiltration of my identifying information, and then being saddled with the "responsibility" for it. The solution is not to make it even more automated, but to generally never to accept any credential except as a revokable guarantee - doing business as a large corp you should accept the risk of fraud, and presume your clientelle are not who they say they are.
No.
Several trips to a government office, had to get a new set of ID, and wait weeks, all while there was important communications waiting for me on one of the dozens of subordinate government sites which were time sensitive but no one could provide me by an alternative method....
I am just waiting to hear the first story of someone going to prison because they couldn't get the message the tax man sent due to the tax man not letting them read the message....
I am against government overreach yet these people really seem to want to change my mind.
I'm sure it happens, and I know the bar for becoming a notary public (official able to notarize documents) isn't that high, but I haven't heard about a ton of fraud where things were falsely notarized. I suppose accessible notarization is a positive thing, at least as long as fraud doesn't become a problem with the system.
I'm sure this is an unpopular idea on HN, but at least it's a way that our governments could use facial recognition/fingerprints/retina to reduce fraud.
However, in the case of the victim, her owing $1.2mm in penalties hinges on her identity being used as the owner of some domain names that contain these brands' names.
I suppose if the victim had "infinite resources" the next step as the victim would be to file a lawsuit against the domain name registrars for claiming she owned the sites. If the registrar would remove her stolen identity from the site then the suit would have no basis to link her to the domain names and she would be cleared.
But then again, what incentive would a domain name registrar have to remove your stolen ID as the owner? If they simply agreed to do it when asked, then anyone could send a fake letter to the registrar claiming you don't own your DNS records and remove you as the owner of them.
Genuine question to HN readers -- if you woke up tomorrow and found a whois entry that had your name and details listed as owner for a site that traded in illicit goods and/or morally objectionable content, how would one go about correcting that?
This is just off the top of my head. It is a huge headache that will trouble you for a few years.
> had your name and details
I was assuming the worst.
I had a paypal account. They demanded copies of my govt. ID. I refused and said close the account. I only ever used it to make payment to web shops using my credit card.
Paypal refused repeatedly to simply close the account given their change in terms of service to which I do NOT agree.
Will someone hack into paypal? Absolutely they will and it will have happened multiple times since this debacle. Will someone hacking paypal then use this account which should not exist to do something that causes a problem for me?
Paypal are responsible for this. This is 100% paypal's problem. Paypal should be on the wrong end of the most expensive litigation seen in this are from which they do not survive.
Paypal's actions in this area are quite deliberate and they know and understand the consequences to people.
Paypal are foul.
[1] I have been in court three different times and seen the wrong defendant brought from the jail to be released since they aren't the person being sought by the indictment, but a case of misidentification by law enforcement. Quite how these people managed to alert the jail authorities to the problem I do not know; having spent significant time in jail I have no idea how you would get any personnel to take seriously the idea that you "aren't supposed to be there."
Furthermore, no sane lawyer would hope to recover such large numbers from a single mother of four children. There is no value in prodding a legal system to render a pointless judgement against a plaintiff who is very likely not responsible for the crime.
Can we see these documents?
I would've used the money she spent on a US IP lawyer to sue Medibank for negligently allowing her personal information to be hacked and sold on the dark web. At the very least I hope she's part of the class action.
The next big data breach in Australia will be from the wave or realestate rental “startups”, it’s only a matter of time.
The sites are badly designed which doesn’t give much faith in security. Also the largest being a Murdoch subsidiary which I guess the data conveniently has huge money value for ad targeting…
The online rental application companies collect (require) more data than any paper rental application form, credit card/bank/mortgage application, or visa application. It’s also unregulated! They’ve positioned themselves so a large number of rental applications have to go through them to apply. The amount of detailed sensitive pii data they hold has to be huge. It’s a treasure trove for any hacker and an easier target than a bank or insurance company.
Do connecting flights in the US count? It's possible also that airlines can reroute flights to connect through the US.
But sticking your head in the sand and complaining about it isn't going to get you very far.
Imagine yourself in their situation, having to defend a legal case in court in a place where you've never been to that has no bearing on anything you've done in your life. That makes the world's population open to being sued for profit in these courts because the courts simply don't do their job. A mistake is when you pass the pepper instead of the salt. This is ruining someone's life.
From TFA:
"Ms Luke has engaged an intellectual property lawyer in the United States, with an initial engagement fee of $US10,000 ($14,800), in a bid to have the rulings overturned and the damages retracted. "
"The single mother of four said the situation was taking its toll.
"The anxiety that this causes, not knowing if they are going to come and take our house, can they freeze my assets, can they get access to my bank accounts?
"We just don't know and it really is a case of guilty until I can prove otherwise.""
That engagement fee is on the low side and yet I think that 99% of the people that might get caught up in stuff like this have absolutely no way of paying that kind of money to correct something they have part in. Besides, the suggestion that you can recoup your legal fees is not really fair: in practice you won't be able to recoup all your fees and you certainly won't be able to recover your time or the stress.
This is fundamentally unjust and classic bully boy behaviour by American courts and terrible corporate citizens.
This person has been dragged into an expensive American civil case .
She was clearly contactable as the corps had found her yet she was contacted with what any person who has any cybersecurity training would dismiss as a spam email.
The jurisdiction is a place she has never been.
This should case should have been thrown out, instead she got a summary judgement.
In Australia she could automatically be awarded costs at trial. Here she's going to have to counter sue.
And last but perhaps most significantly, it's clearly not her. Sure, we don't hear about any of the ones they knock back, but this shit would not even get close to getting up in a good legal system.
https://en.wikipedia.org/wiki/List_of_United_States_extradit...
Wait, what? I thought habeas corpus was a thing in the US?