FTC Business Blog

  • FTC’s AppFolio case: The Fair Credit Reporting Act does more than just abide
    by lfair on December 8, 2020 at 7:16 pm

    FTC’s AppFolio case: The Fair Credit Reporting Act does more than just abide lfair December 8, 2020 | 2:16PM FTC’s AppFolio case: The Fair Credit Reporting Act does more than just abide By Lesley Fair Cult classic The Big Lebowski proves that mistaken identity can be entertaining on film. But for people looking to rent a house or apartment, it wasn’t so entertaining when tenant background reports about them provided by California company AppFolio included someone else’s convictions and evictions. An FTC settlement that includes a $4.25 million civil penalty reminds businesses like AppFolio of the Fair Credit Reporting Act’s requirement that they follow reasonable procedures to ensure the accuracy of information in their reports. Consumer reporting agency AppFolio assembles and merges information obtained from other CRAs to create background screening reports, which it then sells to property managers. Given the harmful impact inaccuracies can have on consumers looking for a home, a job, or some other necessity, the Fair Credit Reporting Act requires that CRAs like AppFolio “shall follow reasonable procedures to assure maximum possible accuracy of the information concerning the individual about whom the report relates.” In addition, the law requires CRAs to exclude certain obsolete information. But according to the FTC, before including criminal records, evictions, etc., in its background reports, AppFolio didn’t have procedures in place to adequately review the accuracy of the information it received from vendors. As a result, the complaint alleges that: AppFolio failed to follow reasonable procedures to assess whether the identifiers in criminal records and eviction records in its reports reasonably matched the applicant; AppFolio failed to follow reasonable procedures to assess whether there were internal inconsistencies in the identifiers or results indicating that the company was including information about multiple people in one report; AppFolio failed to follow reasonable procedures to assure that criminal records and eviction records in its reports accurately reflected the disposition, offense name, and offense type; and AppFolio failed to follow reasonable procedures to prevent the inclusion of multiple entries for the same criminal or eviction case in one report. The FTC says those lapses had serious practical consequences. For example, AppFolio’s tenant background reports sometimes included information about other people with different names or dates of birth or misrepresented criminal or eviction records. The complaint also alleges that in violation of the FCRA, AppFolio included evictions and non-conviction criminal records that were more than seven years old. In addition to the $4.25 million penalty, the proposed settlement requires AppFolio to maintain reasonable procedures to ensure the maximum possible accuracy of information in its reports. The order also prohibits the company from including non-conviction criminal or eviction records older than seven years. The case suggests two other compliance takeaways for CRAs. Caveat (re)venditor? Our Latin is atrocious, but the principle is sound. The FCRA’s requirement of “reasonable procedures to assure maximum possible accuracy” applies to companies that compile the information themselves and to resellers like AppFolio that put together reports based on data from vendors. It’s a risky – and illegal – practice simply to pass along what others have told you without an appropriate process for assessing the accuracy of the information. For more top-line tips, read What Tenant Background Screening Companies Need to Know About the Fair Credit Reporting Act. Respond and reassess. The FTC says AppFolio received complaints disputing the accuracy of information in its reports, but didn’t change its practices to address those failures. It might not seem like it at the time, but consumer complaints can be an effective tool for paving potholes in your procedures. How would your company respond in similar circumstances? In case you thought we wouldn’t close with a comparison between The Big Lebowski and the Fair Credit Reporting Act, think again. As Walter Sobchak said to a guy who crossed the lane’s foul line, “Smokey, this is bowling. There are rules.” To paraphrase Walter, “This is the FCRA. There are rules.” And the FTC expects companies to honor them.  

  • Navigating the world of kids’ marketing: Best Practice Principles from ICPEN
    by lfair on August 17, 2020 at 3:59 pm

    Navigating the world of kids’ marketing: Best Practice Principles from ICPEN lfair August 17, 2020 | 11:59AM Navigating the world of kids’ marketing: Best Practice Principles from ICPEN By Stacy Feuer, Assistant Director for International Consumer Protection, FTC As parents know, kids spend a huge amount of time online, especially now with COVID-19 school and camp closures. They get ideas from influencers on social media and video platforms, make purchases on their smartphones, and influence a lot of family spending. This phenomenon is not limited to the U.S. alone. Recent data from the Organization for Economic Co-operation and Development shows that, on average, kids around the world spend at least three hours online outside of school on a typical weekday, and more than three and a half hours on a typical weekend. Businesses have noticed, and are finding new ways to reach kids on their smartphones, tablets, and laptops, sometimes with personalized messages, no matter where they live. In response, the International Consumer Protection Enforcement Network (ICPEN), a network of consumer protection agencies from over 60 countries, developed Best Practice Principles for Marketing Practices Directed Towards Children Online. If you advertise abroad, or advise clients who do, you might want to check out ICPEN’s best practices so you can understand the range of issues that concern consumer protection agencies and the variety of approaches they use to ensure marketing to children online complies with the laws in their jurisdictions. The ICPEN Best Practices Principles are high level principles: They aren’t an enforcement statement or a guide on how to comply with laws in any particular jurisdiction. For tips on complying with the FTC’s truth-in-advertising advertising standards for marketing to kids in the United States, check out this Business Center page and these updated FAQs on complying with the Children’s Online Privacy Protection Act. The FTC is a member of ICPEN, which promotes cross-border cooperation and coordinates the cross-border consumer complaint website, econsumer.gov. ICPEN developed the best practice principles during the Presidency term of Colombia’s Superintendence of Industry and Commerce. To learn more about ICPEN and its work, please visit www.icpen.org.  

  • The letters of the law: 35 more companies warned about questionable COVID claims
    by lfair on June 4, 2020 at 4:13 pm

    The letters of the law: 35 more companies warned about questionable COVID claims lfair June 4, 2020 | 12:13PM The letters of the law: 35 more companies warned about questionable COVID claims By Lesley Fair FTC staff sent the latest round of warning letters to 35 businesses alleged to have made unsubstantiated coronavirus prevention or treatment claims. What they sold diverges widely – IV vitamin treatments, products containing silver, patches purporting to block electromagnetic radiation, etc. – but they have one thing in common: According to the FTC, their claims aren’t supported by sound science. Here are the companies that received the letters. Arizona Natural Medicine Physicians.  On a webpage titled Coronavirus: Supplements, Herbs & Homeopathic Remedies, the office claimed to offer “homeopathic injections such as Engystol which helps support immune function and prevent infection.” Bixa Human.  On its website, the company pitched products it sold – including BioBija Complex and Victoria T3 – as “the best way to boost your immunity and protect yourself from the coronavirus.” Bodhi Glyphix.  In Facebook posts, the New York business promoted the sale of products it sold by stating, “Our Silver Biotic Formula is patented and has studies showing it’s effective against covid viruses.” Brexo Bio.  The California company claimed on YouTube and Facebook that its stem cell treatments “can be administered intravenously and by inhalation through a nebulizer to treat lung damage caused by COVID-19 . . . .” Cho Acupuncture.  For consumers who are “[e]xperiencing respiratory problems (Coronavirus) and need treatment,” the Georgia business claimed to “provide herbal medicine that will help with this virus. There are now several case studies that are being treated by the herbal medicine in China. These cases have had great success in getting over the virus.” Cory’s SEOM.  In promoting a product called Virus Killer, the California business stated, “One of the essential oils in our mix has already been proven in medical testing to kill the SARS virus, which is a subset of the Corona Virus. We believe that, due to the similarities in viruses, there is an excellent chance that our products will also be very effective at killing the Covid-19 virus.” Doll House Med Spa and Clinic.  In response to the question How can ozone therapy help with COVID-19?, the San Antonio clinic – which offers those services and others – claimed it “block[s] the virus’ ability to replicate by balancing the cellular redox state” and “improves oxygenation to prevent scarring of the lungs and protect vital organs from viral damage.” Dramov Naturopathic Medical Center.  From a homepage hyperlink labeled COVID-19 / CORONAVIRUS INFORMATION, the Oregon company took consumers to a retail website promoting “Viral Immune Support” supplements. Dr. Don Colbert.  In marketing materials titled Dr. Colbert’s Keys to Avoid COVID-19 (Corona Virus), the Texas doctor sold “Supplemental Options for Prevention,” including Divine Health Green Supreme Food and Divine Health Multivitamin. Dr. Eric Nepute.  In a Facebook Live discussion of coronavirus, Missouri-based chiropractor Dr. Nepute stated, ““Guess who’s not sick. My patients. Guess why? Cause they’ve been getting vitamin IVs for months, weeks, or years. Guess what else is not going to happen to them? They’re not going to have other problems. Why? Because they’ve been getting adjusted regularly, because adjustments help improve the nervous system, which helps improve the immune system. Period.” East Valley Naturopathic.  In advertising its services, the Arizona office stated, “to treat pneumonia and hyper inflammation caused by COVID-19, vitamin C has been given at high doses,” both orally and as an IV. Enliven.  On a Facebook post titled Coronavirus: Is High-Dose Vitamin C the Answer?, the Texas company pitched products it sold by stating, “With even modest amounts of supplemental vitamin C, deaths will decrease. In a study, modest amounts of supplemental vitamin C (200 mg of vitamin C per day) resulted in an 80% decrease in deaths among severely ill, hospitalized respiratory disease patients.” Evergreen Naturopathic.  Based in Spokane, the office claimed on its Novel Coronavirus (COVID-19) FAQ page, “[W]e offer our patients personalized herbal tinctures to directly confront the viral infections that are most prevalent throughout the year while strengthening and supporting both the immune system and the sensitive tissues that are most susceptible to these infections.” The Feed.  The Boulder, Colorado, company promoted products it sold, including Ortho Molecular D/K2 (Vitamin D) and Quicksilver Vitamin C, on its website and in Facebook ads. For example, one ad included a graph that showed a “98.9% death rate” for coronavirus for people deficient in Vitamin D vs. a “4.1% death rate” for people with normal Vitamin D levels. GlyCop Co-op.  In marketing materials titled Coronavirus Research, the co-op claimed, “The bottom line for strengthening the immune system to fight the CV [coronavirus]” is to ingest large amounts of Vitamin C – which the Boise business sells. Gonino Center for Healing.  For consumers concerned about COVID-19, the Texas office promoted IV Ozone therapy, IV Vitamin C therapy, hyperbaric oxygen therapy, Quercetin, and other products and services it sells. According to a Facebook post, “I wanted to share a quick update on the #Coronavirus scare. . . . If I become infected, besides bedrest, fluids, and prayer, my plan will be iv ozone morning and afternoon on days 1 and 3, iv Vitamin C on days 2 and 4.” Hawaii Naturopathic Retreat.  On a page titled COVID-19 Testing and Prevention, the Hilo, Hawaii, business offered “immune boosting packages to help you protect yourself against the coronavirus. . . .” Those included both “Antiviral Supplements Drop Shipped Directly to You” and a variety of IV treatments, injections, an infrared sauna, and “colonics with probiotics.” Health Associates Medical Group.  In marketing materials titled Important Covid 19 Information to Prevent and Possibly Treat This Virus, the Sacramento office promoted its services by stating that “[i]ntraveous Vitamin C was used by the Chinese as part of their protocol to improve tissue oxygenation and prevent the ‘Cytokine storm’ in Covid 19 patients.” Hot Springs BioFeedback.  Under the heading “Diagnosed with COVID-19? I’ve got the answer! I’m in total recovery!,” the Texarkana, Texas, business recommended products containing silver. According to the company, silver “binds to the DNA of the virus-cell, preventing it from multiplying” and “prevent[s] the transfer of the virus from one person to another by blocking the ability of the virus to find a host cell to feed on.” Innovation Compounding.  In marketing materials titled Coronavirus: Is High-Dose Vitamin C the Answer?, the Georgia company promoted its Vitamin C infusions by stating, “China is conducting a clinical trial of 24,000 mg/day of intravenous vitamin C to treat patients with coronavirus and severe respiratory complications. . . .” Julie E. Health.  The Redondo Beach, California, business promoted its Corona Virus Prevention and Treatment Kit, which included EMF (electromagnetic radiation) Blocking Patches and supplements. According to the company, the kit is “your first line of defense nutritionally speaking to prevent the corona virus.” KimberTouch Technologies.  In online marketing materials titled Professionals Are Here – Real Protocol for Coronavirus, the company promoted an “anti-viral protocol” consisting of Vitamin C, silver, silver nasal wash, and oxygen. Love Acupuncture.  In promoting products as “Alternative treatments for COVID-19 (coronavirus),” the Oregon business stated, “[T]he Chinese government distributed Chinese herbal medicine to everyone with covid-19 in the hospital” and “yielded a 94% improvement rate . . . .” The company added, “While we are not allowed to say these herbs treat COVID-19[,] what we can tell you is that these preventative formulas are being used in China and the reports are showing a positive difference.” Natural Health 365.  In marketing materials titled Consider Vitamin C for acute respiratory distress syndrome from COVID-19, Medical Journal says, the Florida company promoted its products by claiming “Doctors recommend high dose vitamin C as potential treatment for COVID-19 sufferers, backed by decades of scientific research” and “High-dose glutathione shows promise in addressing respiratory distress in patients with COVID-19.” Nutritional Healing Center of Ann Arbor.  The office featured a video titled Immune Supplement Bundles that stated, “In the last few weeks and months, there’s a very scary virus that everybody’s talking about. And in the medical research, I have found at least twenty different nutrients, herbs, and vitamins that kill this virus.” The video promoted a variety of products sold by the Center, including ones called The Guard Dog package and The Sheriff. Organic Hawaii, LLC.  Using affiliate marketing links, the Honolulu business advertised “Best Natural Supplements, Vitamins, and Minerals to boost the immune system and help protect against COVID-19 coronavirus,” and linked to websites selling – among other things – liposomal Vitamin C, hemp seeds, pumpkin seeds, Lion’s Mane, Turkey Tail, elderberry syrup, and mushrooms. Post Falls Naturopathic Clinic.  The Idaho business said it has used “energetic signatures of the Coronavirus and influenza” to create Covid-19 & Flu Immune Booster, “a new homeopathic remedy to boost your immune system” and provide general immune support for colds, flu and the Coronavirus. Pure Prescriptions, Inc.  The California company urged consumers to “Do This to Help Lower Your Risk of Getting Coronavirus!” Among its recommendations was “supplementing with NewGreens,” a product for sale in its online store. Renaissance Health Centre. To promote its products and services, the Las Vegas clinic claimed that “homeopaths [in China] report that the symptoms of people who get the Coronavirus point towards” the use of Gelsemium, Bryonia, Eupatorium Perf., and Thymulin 9C. The clinic also touted its intravenous hydrogen peroxide and ozone therapies. Restore Med Clinic.  In an Instagram post titled COVID-19 What should you be doing to optimize your health?, the clinic included a list of vitamins, but added, “Over the counter supplements and herbs are both convenient and easy, yet for a more effective protection,” it recommended “High-dose Vitamin C IV Therapy,” including “COVID-19 Immunity Boost” IV drips available at the clinic. Revival Hydration.  The San Francisco company promoted its IV vitamin therapy services by stating, “Keep Corona out with our Immunity treatment! . . . Our immunity treatment utilizes the most powerful immunity-strengthening supplements on the market.” According to the company, its treatment “Expedites Recovery exponentially” and “Makes you feel grateful your suffering period is cut in half at a minimum.” Sage Integrative Medicine Clinic. On a webpage titled Coronavirus Updates: Clinic News & Immune Support Tips, the Edmonds, Washington, clinic promoted its “High-dose IV Vitamin C.” It made similar recommendations on a page with the heading Coronavirus: The Top Ways to Protect Yourself and Your Family. Tulsa Chiropractic Rehab.  In promoting treatments it sold, the Oklahoma office claimed, “Certain vitamins and supplements are proving effective in the fight against coronavirus: particularly vitamin D, vitamin C, and Zinc!” Utopia Silver.  In discussing products it sold, the Utopia, Texas-based company said, “If you’re actually fighting a cold or influenza OR corona-virus, you may need 10,000-20,000 [of Vitamin C] a short period of time along with a colloidal silver supplement.” Vero Clinics.  Next to a photo of products it sells, the Decatur, Illinois, clinic stated, “I know there’s a lot of anxiety and confusion regarding the recent pandemic that we’re all experiencing. I just want to make everyone aware there a number of immune-boosting modalities offered here at Vero Clinics. These include IV nutrition, high dose Vitamin C, IV silver, IV ozone, peptides, et cetera.” Like the dozens of other warning letters the FTC has sent, these letters remind businesses that no study is currently known to exist that substantiates their COVID-19 claims. Therefore, they “must immediately cease making all such claims.” FTC staff expects to hear from back from them within 48 hours, describing what they’re doing to address these concerns.  

  • Thinking about making Coronavirus claims? Read the latest FTC warning letters first.
    by lfair on April 14, 2020 at 3:07 pm

    Thinking about making Coronavirus claims? Read the latest FTC warning letters first. lfair April 14, 2020 | 11:07AM Thinking about making Coronavirus claims? Read the latest FTC warning letters first. By Lesley Fair It’s FTC Advertising 101: Don’t make claims about serious medical conditions unless you have solid proof in hand to substantiate what you say. It’s been the law for decades and now more than ever, it’s essential for advertisers to honor that fundamental principle. And yet companies continue to market everything from facial brushes to IV drips with promises to prevent, treat, or cure Coronavirus – claims the FTC calls into question in a new round of warning letters. In addition to other warning letters sent in recent weeks to companies making Coronavirus claims, these ten companies just received letters from FTC staff. Bioenergy Wellness Miami. The FTC says the Florida company claimed on its website that devices it sells emit sound frequencies that “target Coronavirus/SARS viral infections, and can be used either as homeoprophylaxis or at the onset of flu-like symptoms. . . .” Face Vital LLC. According to the FTC, the Miami Beach business marketed its “Face Vital Sonic Silicone Facial Brush” as a way to “fight off Coronavirus” and suggested consumers could “RAMP UP YOUR BEAUTY AND CLEANSING REGIMEN, FIGHT OFF CORONA” by using its product. LightAir International AB. On its website, the Swedish company claimed, “The corona virus can in various ways be air-borne . . . . IonFlow air purifiers are scientifically proven to efficiently prevent spread of air-borne viruses.” MedQuick Labs LLC. According to statements the Arkansas company made on its Facebook page, “The CoronaVirus, as well as the flu, has everyone in a frenzy right now. One of the best things you can do is make sure your immune system is ready to fight off anything nasty. Boost your immune system with our improved Immunity Boost drip! You can wash your hands all day long but one of the best defenses against ANY illness is to boost your immune system and the best way is by putting Vitamin C and other immune building vitamins straight into your bloodstream.” New Performance Nutrition. The warning letter to the Los Angeles business cites this statement the company had on its website: “NPN ANTI-VIRUS KIT is a bundle of immune defense supplements, hand-picked by NPN Owner/Founder Matt Mahowald, that will target and increase your immunity to help ward off the COVID-19 virus.” PuraTHRIVE LLC. The Colorado company’s website promoted its Liposomal Vitamin C products by claiming “Experts in the field are suggesting that regular dosing of Vitamin C could help to prevent the Coronavirus . . . . ‘The coronavirus can be dramatically slowed or stopped completely with the immediate widespread use of high doses of Vitamin C. Bowel tolerance levels of C taken in divided doses throughout the day, is a clinically proven antiviral, without equal.’” Resurgence Medical Spa, LLC. The warning letter to the Arlington, Texas business cites Facebook and Instagram posts that said, “More and more research is showing that high doses of Vitamin C could both prevent and treat Covid-19. Whether you’re experiencing symptoms or trying to keep from getting sick, call us today to schedule an appointment for a High Dose Vitamin C plus Immunity Booster IV infusion.” Rocky Mountain IV Medics. The Colorado company advertised its IV treatments through social media and on its webpage, using claims like this: “Coronavirus Symptoms Treatment Tests are underway and IV Vitamin C treatments are starting to show promising results! If you’re looking for IV Vitamin C therapy, we have ASAP and prescheduled appointments available.” The website also linked to an article that said, “Shanghai Medical Association has released an expert consensus statement on the comprehensive treatment of COVID-19 where they endorse the use of high-dose IV vitamin c for the illness.” Suki Distribution Pte. Ltd. The Singapore-based company’s said on its website, “As the coronavirus COVID-19 pandemic is spreading globally, our clients ask whether our products can help prevent or treat Coronavirus. The good news is that several of our products may play a role in strengthening the immune system or in fighting the Coronavirus.” The website further described a product as a “safe Japanese drug with anti-Coronavirus effects” and that a laboratory study concluded that the purported active ingredient cepharanthine “can be applied for the prevention and treatment of Human Coronavirus infection.” Vita Activate. According to the warning letter, the Canadian company claimed on its website that its Natural Chaga Mushroom “may prevent invaders such as the corona virus. Just a few sprays a day can boost your immunity effectively . . . Very rich in source of magnesium, zinc, and selenium that have anti-corona virus properties. Get ready and be prepared to fight off bacteria and harmful airborne diseases with the powerful anti-viral, anti-bacterial Chaga Mushroom.” The letters lay it on the line that the companies must ensure they’ve stopped making Coronavirus prevention, treatment, or cure claims for the cited products. Here is a sample of what the letters say: It is unlawful under the FTC Act . . . to advertise that a product can prevent, treat, or cure human disease unless you possess competent and reliable scientific evidence, including, when appropriate, well-controlled human clinical studies, substantiating that the claims are true at the time they are made. For COVID-19, no such study is currently known to exist for the product identified above. Thus, any coronavirus-related prevention or treatment claims regarding such product is not supported by competent and reliable scientific evidence. You must immediately cease making all such claims. These ten Coronavirus warning letters follow seven FTC-FDA letters announced on March 9th and additional joint warning letters sent since then. The message to marketers should be unmistakable. Regardless of what kind of pill, potion, device, or what-have-you your company promotes – including through social media – if you suggest or imply Coronavirus prevention or treatment claims, your practices will attract scrutiny from the FTC.  

  • Voice cloning: Where WOW meets OMG
    by lfair on January 16, 2020 at 6:39 pm

    Voice cloning: Where WOW meets OMG lfair January 16, 2020 | 1:39PM Voice cloning: Where WOW meets OMG By Lesley Fair Have you had this experience? You hear about a remarkable innovation, but before you can finish the phrase “That’s amaz . . . .” you’ve already jumped ahead to the questions and concerns it raises. That’s how many people are responding to voice cloning – emerging technologies that let users make near-perfect reproductions of a person’s voice. It’s also the subject of You Don’t Say: An FTC Workshop on Voice Cloning Technologies, scheduled for January 28, 2020. You’ll want to check out the just-announced agenda. Think of the benefits of voice cloning for people who have lost the ability to speak. But now consider the danger if scammers exploit the technologies by using recognizable voices to perpetrate family emergency scams (“I’m in the hospital, Grandpa, and need money ASAP”), business imposter cons (“Wire a payment to our vendor immediately”), or other forms of fraud. You Don’t Say will convene at 12:30 PM ET with remarks from FTC Commissioner Chopra. Next on the agenda: a presentation by Dr. Patrick Traynor, the John and Mary Lou Dasburg Preeminence Chair in Engineering at the University of Florida, on the state of voice cloning technologies. The first panel – which will feature a demonstration of voice cloning – will focus on Good and Bad Use Cases. On the second panel, academics and others will discuss the Ethics of Voice Cloning. The third panel will explore Authentication, Detection and Mitigation. Lois Greisman, Associate Director of the FTC’s Division of Marketing Practices, will present closing remarks at 4:45. You Don’t Say is free and open to the public. Planning to attend in person? The event will convene at 12:30 PM ET on Tuesday, January 28th, at the FTC’s Constitution Center conference facility, located at 400 7th Street, S.W., in Washington, DC. Or you can watch the live webcast from a link we’ll post minutes before the start time. We’ll also live tweet from @FTC using the hashtag #voicecloningFTC.  

  • Mentioning unmentionables
    by lfair on December 6, 2017 at 3:21 pm

    Mentioning unmentionables lfair December 6, 2017 | 10:21AM Mentioning unmentionables By Lesley Fair When it comes to using online negative options to sell unmentionables (or anything else), there are some material terms and conditions that marketers need to clearly mention. That’s the brief but foundational lesson of the FTC’s $1.3 million settlement with online lingerie seller AdoreMe. AdoreMe billed members of its VIP membership program a monthly fee of $39.95 unless in the first five days of the month they either bought merchandise or clicked an online “skip” button – sometimes called the “shop or skip” option. What if people didn’t find anything to buy that month or forgot to skip? No problem, said AdoreMe: “If you do not make a purchase or skip the month by the 5th, you’ll be charged a $39.95 store credit that can be used anytime to buy anything on Adore Me.” (Consumers also could buy items on a pay-as-you-go basis for a higher price.) But despite AdoreMe’s express claim that consumers who paid to be in the VIP program could use their store credits “anytime,” the FTC says that at least from May 2015 to May 2016, the company didn’t honor that promise for certain people. The complaint alleges that if consumers cancelled their VIP memberships – or initiated chargebacks with their credit card companies or banks to dispute charges made by AdoreMe – the company cancelled their unused “anytime” store credits. The FTC says that rendered the “anytime” claim deceptive. AdoreMe stopped that practice last year, but didn’t give full refunds to all affected consumers AdoreMe made that “anytime” representation in a number of different places, including in promotional emails, in package inserts, and at the checkout cart. But the FTC says AdoreMe didn’t clearly and conspicuously disclose its policy of forfeiting the store credits of consumers who cancelled their VIP memberships. According to the complaint, people were able to enroll in the VIP program without seeing the policy, which appeared more than 1,000 words into the terms and conditions of the VIP program, which was accessible from a hyperlink at the bottom of the AdoreMe website. What’s more, the hyperlink often appeared below the fold – in other words, below the portion of a webpage users can see without scrolling down. The FTC also alleges that AdoreMe made it difficult for consumers to cancel their VIP memberships – memberships that were costing people $39.95 every month. For a period of at least a year, the company didn’t let people cancel on the AdoreMe website and only honored telephone cancellations. But even if consumers reached the cancellation line, they often experienced a lengthy wait. Just as an example, on February 10, 2014, consumers were kept on hold for over 11 minutes. Consumers trying to cancel on December 10, 2015, could expect a phone wait of more than 32 minutes. Then there was AdoreMe’s five-question “Membership Quiz” consumers had to complete as part of the cancellation process and a series of additional pages they had to navigate. Those are just some of the barriers to cancellation the FTC cited in its lawsuit. Count I of the complaint alleges that AdoreMe violated the FTC Act by misrepresenting its “anytime” store credit policy. Count II charges the company with violating the Restore Online Shoppers’ Confidence Act (ROSCA) by failing to provide consumers with a simple method for stopping recurrent charges for negative options. In addition to $1.3 million in refunds for consumers, the stipulated order requires AdoreMe to clearly disclose key terms of negative options and other offers in a number of instances. For example, if AdoreMe claims that a product sold via negative option is discounted (or free), it must clearly disclose, in close proximity to that claim, the costs, deadlines, and actions required by the negative option program – and that it’s not just advertising a discount. AdoreMe also must get consumers’ express informed consent before billing them for charges related to any negative option offer, obtaining consent through a checkbox, signature, or similar method placed near disclosures of the costs, deadlines, and actions required by the negative option program, including how consumers can avoid charges. The settlement also requires AdoreMe to promptly send consumers confirmations of their orders with similar disclosures and without any upsells, additional product or service offers, or other advertising or marketing. If you or your clients use online negative options, avoid the kind of underwear snare alleged in the AdoreMe complaint by reviewing your obligations under ROSCA. Clearly disclose the terms of the program up front and keep the cancellation process simple and consumer-friendly.  

  • $20 million FTC settlement requires Uber to have proof for earnings, auto financing claims
    by lfair on January 19, 2017 at 9:10 pm

    $20 million FTC settlement requires Uber to have proof for earnings, auto financing claims lfair January 19, 2017 | 4:10PM $20 million FTC settlement requires Uber to have proof for earnings, auto financing claims By Lesley Fair In promotional materials to attract prospective drivers, ride-hailing company Uber Technologies touted how much money drivers would earn and the favorable terms they could get by financing a car through Uber’s Vehicle Solutions Program. But according to an FTC complaint, Uber exaggerated those earnings claims and misrepresented the terms of its Vehicle Solutions Program. A $20 million settlement stands for the proposition that established truth-in-advertising principles apply to any company making earnings or auto financing claims – and that includes Uber. Uber said on its website that uberX drivers’ “median income is more than $90,000/year/driver in New York and more than $74,000/year/driver in San Francisco.” The FTC alleges that for at least the year before, the median income earned by uberX drivers in those cities was thousands less than that. Other ads touted hourly rates of $25 for drivers in Boston and Philadelphia, but the FTC says fewer than 10% of them made that much. In addition, Uber told drivers, “[O]wn a car for as little as $20/day” ($140/week) or lease a car with “payments as low as $17 per day” ($119/week). Uber also promised that the company’s Vehicle Solutions Program “connects drivers with any kind of credit history to the best financing options available” and that drivers who lease cars through its program would have “unlimited miles.” The complaint challenges those claims as deceptive. The FTC says that from at least late 2013 through April 2015, drivers who participated in the program paid more than advertised, received worse rates on average than consumers with similar credit scores, and are bound by leases with mileage limits. In addition to a $20 million financial remedy, the order puts protections in place to prohibit false or unsubstantiated claims about drivers’ earnings, auto financing, or leasing terms.

  • ASUS case suggests 6 things to watch for in the Internet of Things
    by lfair on February 23, 2016 at 5:14 pm

    ASUS case suggests 6 things to watch for in the Internet of Things lfair February 23, 2016 | 12:14PM ASUS case suggests 6 things to watch for in the Internet of Things By Lesley Fair The router is Grand Central Station for home technology. It manages the connections between all of the smart devices in the home, from the computer in the den and tablet on the coffee table, to the smart thermostat on the wall and internet-connected baby monitor in the nursery. Consumers expect that route to be a limited access highway with the router forwarding data securely while blocking unauthorized access. But an FTC complaint against tech giant ASUSTeK Computer, Inc. – most people know them as ASUS – challenges as unfair and deceptive the company’s failure to secure the routers and “cloud” services it marketed to consumers. The case also offers insights for other businesses entering the Internet of Things.How ASUS advertised its products.  ASUS advertised that its routers had numerous security features that could “protect computers from any unauthorized access, hacking, and virus attacks” and “protect [the] local network against attacks from hackers.” But according to the FTC, ASUS’s routers didn’t live up to those promises. What’s more, the company’s routers included services called AiCloud and AiDisk that allowed consumers to plug a USB hard drive into the router to create their own “cloud” storage, accessible from any of their devices – a kind of central storage hub for the smart home. While ASUS advertised these services as a “private personal cloud for selective file sharing” and a way to “safely secure and access your treasured data through your router,” the FTC alleges they were anything but secure.Where ASUS went wrong with its routers.  Despite the router’s vital role in protecting the home network, the FTC says ASUS didn’t take basic steps to secure the software on its routers. For example, consumers managed the router (including those security features) through a web-based interface we’ll call the admin console. But by exploiting pervasive security bugs in the admin console, hackers could change the router’s security settings – even turning off the router’s firewall, flipping on public access to the consumer’s “cloud” storage, or configuring the router to redirect consumers to malicious websites. In fact, one exploit campaign that specifically targeted numerous ASUS router models did just that, reconfiguring vulnerable routers so hackers controlled consumers’ web traffic. As the complaint alleges, far from protecting consumers’ home networks, ASUS’s routers let hackers wreak havoc on them.ASUS’s insecure “cloud” services.  ASUS’s “cloud” storage services weren’t secure either. According to the FTC, anyone who knew the router’s IP address – a walk in the park for a hacker – could bypass the AiCloud service’s login screen and access consumers’ storage devices without any credentials, leaving consumers’ files wide open on the internet. AiDisk didn’t fare much better. The FTC took issue with that service for relying on an insecure protocol and having a confusing set-up process with insecure defaults. For example, when consumers turned on the service, by default, it would provide anyone on the internet with unauthenticated access to all of the files on the consumer’s storage device. Worse yet, the setup wizard didn’t explain those defaults and didn’t make it clear what was going on. Not to mention that if the consumer tried to create a restricted account, the service preset the login credentials to the same weak username and password (Family/Family) for everyone. All of these security vulnerabilities and design flaws amounted to big trouble for consumers.ASUS’s delayed response and failure to notify consumers.  The FTC says that ASUS could have prevented many problems if it had followed well-known, secure software design, coding, and testing practices. What’s more, security researchers had contacted ASUS to sound warnings, but it often took months – and sometimes over a year – for ASUS to respond.  For example, when one researcher reported that by his estimate, 25,000 consumers had AiDisk storage devices openly accessible on the internet, it was crickets from ASUS. In fact, it was only after a plea from a large European retailer that ASUS started to pay attention to that problem. By then, it was too late.Even more troubling, alleges the FTC, is that when ASUS developed security patches, it didn’t notify consumers. The router’s admin console had a tool that was supposed to let people check if their router was using the latest available firmware (the software built into the router). But as researchers warned ASUS, the upgrade tool wasn’t working as it should. According to the complaint, more than a year went by and consumers were still getting the message that their “router’s current firmware is the latest version” when newer firmware with critical security updates was available.Thousands of compromised routers. This meant that ASUS’s routers and “cloud” services left consumers’ home networks and personal files at the mercy of hackers and identity thieves. You can guess what happened next. Hackers used tools to locate the IP addresses of thousands of vulnerable ASUS routers and that’s where the story gets really interesting. Exploiting AiCloud’s vulnerabilities and AiDisk’s design flaws, they gained unauthorized access to the USB storage devices of thousands of consumers. But they didn’t come and go quietly. They left a text file on the devices that said, “This is an automated message being sent out to everyone effected [sic]. Your Asus router (and your documents) can be accessed by anyone in the world with an internet connection.”ASUS’s security claims may have been deceptive, but one thing turned out to be true: the hackers’ warning that consumers’ routers and documents were accessible to anyone in the world. For example, one consumer reported that ID thieves used sensitive information on his USB storage device, including tax returns and other financial data, to rack up unauthorized charges and make a mess of his identity. Others complained that a major search engine had indexed the personal files their vulnerable ASUS routers had exposed, making them searchable online.The FTC’s complaint.  The lawsuit challenges as false or misleading ASUS’s claims that it took reasonable steps to ensure its routers protected consumers’ local networks from attack, that AiCloud and AiDisk were secure ways for people to access sensitive information, and that its firmware upgrade tool was accurate. The complaint also alleges that ASUS’s failure to take reasonable steps to secure software for its routers was an unfair practice.How ASUS will have to change.  The proposed order includes security provisions that have become standard in FTC settlements, but there’s something else. If there’s a software update or other steps consumers can take to protect themselves from a security flaw in the future, ASUS must notify them. Importantly, the settlement makes it clear that merely posting a notice on its website isn’t enough on its own. (Who goes to their router manufacturer’s website regularly?) In addition, the proposed order requires that ASUS offer consumers a way to register to receive security notices through direct communication, like email, text message, or push notification. In the Internet of Things, where consumers often “set it and forget it,” these types of direct communications can be critical tools in making sure consumers get the message. You can file a comment about the settlement by March 24, 2016.If the Internet of Things intrigues your company, the case offers six tips for maintaining careful connections.Start with security.  While ASUS’s routers suffered from a host of classic vulnerabilities, the problem with AiDisk went beyond bugs or glitches. According to the complaint, it was unsafe from the get-go both in the company’s choice of an insecure protocol and in its confusing and insecure user interface. Yes, you want to get your product to market ASAP, but take the time to design security in at the outset. That’s a particularly important consideration in the Internet of Things where the insecure design of one product can affect multiple connected devices.  Design your products through customers’ eyes.  If you sell a connected product for home use, customers are likely to run the gamut from newbie to pro. So how can developers communicate with people at both ends of the spectrum? Here’s a perspective to consider. Less tech-savvy consumers often complain about products that are too complicated. But have you ever heard a sophisticated user grumble that an interface was too clear or too straight-forward?Make it easy for people to select the safer option from the start.  Pay particular attention to the security implications of your defaults and set-up procedures. Consumers who get discouraged by a complicated maze of screens may configure their devices improperly or may stick with out-of-the-box choices. That’s why it’s dangerous to set your system defaults as “open” – or insecure, as was the case with AiDisk. It’s great to offer customizable features for the technology dab hand, but wise developers consider the benefits of security by default.Heed security warnings. In many recent cases, the FTC has noted that companies didn’t address credible alerts about potential product vulnerabilities. When security issues come to your attention, the wiser course is to investigate and reach out to customers immediately if the concerns prove accurate.Think through how you’ll let consumers know about fixes. Say someone spots a problem and you design a patch to address it. That’s an important first step, but the job’s not done. A security patch is effective only if customers install it. Far-sighted developers build in a what-if contingency plan to address the challenges of notifying people after the fact.Learn the lessons from other FTC cases. According to the FTC’s Start with Security publication, there’s no one-size-fits-all formula for what’s reasonable. But every data security complaint offers lessons about practices that could lead to trouble in certain circumstances. Paragraph 30 of the ASUS complaint recaps dozens of them, including weak default login credentials, choosing insecure protocols when safer ones are readily available, skipping industry-accepted testing, and failing to implement low-cost protections against well-known vulnerabilities.           Looking for more tips? Read Careful Connections: Building Security in the Internet of Things.

  • TracFone’s limits on “unlimited” data lead to $40 million in consumer refunds
    by lfair on January 28, 2015 at 5:09 pm

    TracFone’s limits on “unlimited” data lead to $40 million in consumer refunds lfair January 28, 2015 | 12:09PM TracFone’s limits on “unlimited” data lead to $40 million in consumer refunds By Lesley Fair Certain advertising terms are bound to attract consumer attention: “free,” “no diet or exercise required” – and for people in the market for mobile data plans, “unlimited.” The FTC’s settlement with TracFone Wireless will return $40 million to consumers whose unlimited service was throttled or cut off. What can your company take from the case?TracFone is the country’s largest prepaid mobile phone service provider with approximately 25 million subscribers. Since 2009, TracFone has advertised unlimited service using a variety of brand names, including Straight Talk Wireless, Net10 Wireless, Simple Mobile, and Telcel America. The centerpiece of TracFone’s ad campaigns was “unlimited talk, text, and data” – sometimes described as “unlimited everything” – for about $45 per month. Sure, phone and text services were attractive selling points. But consumers were particularly drawn to unlimited data plans so they could surf the web, stream videos, and use mobile apps without worrying about how much data they used.According to the FTC, TracFone broke the “unlimited data” promise it made to millions of consumers by substantially reduced the speed of their service if customers went over certain fixed limits in a 30-day period. Throttled customers often experienced slow-downs of at least 60% and sometimes even 90%, significantly impairing their ability to engage in the very activities people buy a data plan for. Customers whose service was cut off couldn’t send or receive mobile data at all.Once people began to approach the company’s fixed data limits, TracFone would send them a prerecorded voice message. Rather than describing the company’s data throttling policy, the message just said something like this: “If your excessive data use continues, we may need to suspend or deactivate your data service or terminate your phone service altogether as specified in the terms and conditions of service. . . . ”  But according to the FTC, even TracFone’s terms and conditions often didn’t disclose how it limited customers’ data service.What’s more, the FTC says that until at least September 2013, most TracFone’s ads didn’t explain the throttling policy at all. After that, TracFone started to disclose some information, but not in a way that was clear and conspicuous to consumers. For example, the FTC alleges that TracFone buried it in fine print away from the much more prominent promise of unlimited data or put in on the back of packages where people were less likely to look.Did TracFone’s policy apply just to a tiny percentage of particularly data-hungry customers? No. According to the FTC, TracFone throttled the mobile data service of millions of customers and suspended the service of hundreds of thousands more. Furthermore, the policy had nothing to do with network management and everything to do with an internal TracFone business decision “to control excessive data usage and reduce the high costs related to it.”The complaint charges that TracFone violated the FTC Act by advertising unlimited mobile data service while failing to disclose – or failing to adequately disclose – that it imposed material restrictions on the quantity and speed of data for customers who used more than a fixed amount in a given service period.The settlement requires TracFone to clearly and conspicuously disclose any limits on the speed or quantity of its data service. In addition, the settlement establishes a $40 million fund for customers whose service was affected. Consumers can get more information about the refund program at ftc.gov/prepaidphone.What can other companies take from the TracFone settlement?Mobile products and services may be new(ish), but there’s nothing new about the truth-in-advertising principles that apply. And one of those central tenets is that the FTC looks at representations from the consumer’s perspective. That’s why – to use an obvious example – it’s unwise to make the express claim that a service is unlimited if what you really mean by “unlimited” is, well, “limited.”We’ll keep saying it as long as we have to: If the disclosure of information is necessary to prevent an ad from being deceptive, the disclosure must be clear and conspicuous. If you advertise a service as unlimited, don’t bury key restrictions in blocks of fine print placed where consumers aren’t likely to see them. What principles should companies consider in their approach to disclosures? The FTC staff guide, .com Disclosures: How to Make Effective Disclosures in Digital Advertising, is a good place to start. (Do you advertise on TV or in print? It’s still worth a read.)Like some other recent cases, the TracFone refund program will be coordinated with a pending class action. Of course, that case is separate from the FTC’s law enforcement action, but when it’s in consumers’ interest to have refunds administered that way, we’ll work with all parties to streamline the process.

  • Double duty?
    by wfg-adm109 on June 27, 2011 at 3:57 pm

    Double duty? wfg-adm109 June 27, 2011 | 11:57AM Double duty? By Lesley Fair Sometimes it’s great to put stuff to more than one use.  Think the versatile Swiss Army knife, the iconic Little Black Dress, or the typical elementary school “cafetorium” where kids can eat lunch, shoot hoops, and put on plays.  But when what’s at issue is information from people’s credit reports, that kind of double duty can violate the Fair Credit Reporting Act — as the FTC’s $1.8 million settlement with Teletrack, Inc., makes clear. In FCRA parlance, Teletrack is a “consumer reporting agency.”  Its primary line of work is selling credit reports to payday lenders, rent-to-own stores, non-prime rate auto lenders, and other companies that serve non-traditional credit customers.  Companies use the reports to decide whether they’ll extend credit, and on what terms. When prospective customers apply for credit, they give the payday lender or car lot rafts of personal information.  The company, in turn, passes the data on to Teletrack when they ask for a credit report on the customer. But Teletrack had a sideline business.  In addition to using that information to provide credit reports, Teletrack put it to further use by creating a separate marketing database of people who had applied for credit with payday lenders, rent-to-own stores, etc.  Teletrack then sold their names and addresses to marketers looking to pitch them other stuff.  For example, Teletrack sold lists of people who’d sought payday loans to companies that wanted to use that information to target potential customers. As the FTC’s complaint alleges, those marketing lists are “consumer reports” under FCRA because they contain info about a person’s creditworthiness.  But under FCRA, consumer reporting companies can’t sell credit reports without a specific “permissible purpose.”  According to the FTC, hoping to make a buck by selling marketing lists isn’t one of those “permissible purposes.” Filed in federal court in Georgia, the FTC’s settlement with Teletrack requires the company to change its business practices and imposes a $1.8 million civil penalty.  

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.