Case Library / Physical Social Engineering (Tailgating & Baiting) / American United Mortgage Company Dumpster Diving / Improper Disposal Case (FTC v. American United Mortgage, 2007-2008)

American United Mortgage Company Dumpster Diving / Improper Disposal Case (FTC v. American United Mortgage, 2007-2008)

The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports and financial records in an unsecured dumpster, kept doing it even after a written FTC warning, and paid a $50,000 penalty.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

American United Mortgage Company, a mortgage lender headquartered in Northbrook, Illinois, was the subject of the Federal Trade Commission's first-ever enforcement action under the FACTA Disposal Rule. In February 2006, hundreds of loan-related documents containing consumers' sensitive personal and financial information, including full consumer/credit reports for 36 identifiable consumers, Social Security numbers, and bank/credit-card account numbers, were found discarded in open trash bags in and around an unsecured dumpster near the company's office. FTC staff notified the company in writing in March 2006 that this violated federal disposal requirements, but improperly discarded consumer documents were found in the same unsecured dumpster on at least two further occasions afterward. The FTC's complaint, filed by the Department of Justice on its behalf in the U.S. District Court for the Northern District of Illinois (Civil Action No. 07C 7064) on December 17-18, 2007, alleged violations of the FACTA/FCRA Disposal Rule, the Gramm-Leach-Bliley Act Safeguards Rule (no written information-security program), and the GLBA Privacy Rule (no privacy notices to customers from July 2001 through March 2006). A stipulated final judgment entered January 28, 2008 imposed a $50,000 civil penalty and ongoing compliance and audit requirements.

How the Attack Worked

American United Mortgage, a mortgage lender that collected sensitive consumer data (Social Security numbers, bank and credit-card account numbers, income information, credit histories, and full consumer/credit reports) as part of loan origination, disposed of paper records by placing them in open trash bags in and around a dumpster near its office that was not secured against public access. There was no shredding, pulverizing, or other destruction step before disposal, so intact documents containing consumer report data were left exposed to anyone who accessed the dumpster or surrounding trash. The FTC also alleged the company had no comprehensive written information-security program (GLBA Safeguards Rule) and, from July 1, 2001 through March 2006, failed to give customers the privacy notices required under the GLBA Privacy Rule, meaning the disposal failure sat inside a broader pattern of absent data-handling controls rather than a single one-off lapse.

The Lure & the Tell

There was no deceptive "lure" aimed at a human victim in this case; it is a passive-exposure incident, not a social-engineering pretext. Detection came in February 2006, when hundreds of documents were found discarded in open trash bags near the company's dumpster, including consumer (credit) reports for 36 identifiable consumers. FTC staff sent American United a written warning in March 2006 specifically telling the company to fix its disposal practices. Despite that formal notice, FTC investigators (or their sources) found additional improperly discarded consumer documents in the same unsecured dumpster on at least two subsequent occasions. The repeated recurrence after an explicit warning was the key aggravating fact the FTC cited in seeking penalties rather than a warning letter alone.

Outcome

The U.S. Department of Justice, at the FTC's request, filed a complaint for civil penalties, injunctive and other relief against American United Mortgage Company in the U.S. District Court for the Northern District of Illinois, Eastern Division (Civil Action No. 07C 7064 / docketed as 1:07-cv-07064) on December 17-18, 2007. A stipulated final judgment and order was entered January 28, 2008, imposing a $50,000 civil penalty, a permanent injunction against further violations of the Disposal, Safeguards, and Privacy Rules, and a requirement to obtain independent third-party security audits every two years for 10 years. No criminal charges were brought and no identity-theft victims or fraud losses tied to the exposed documents were identified in the public case record; this was a civil regulatory enforcement action, not a prosecution of an attacker.

Why It Matters

This was the first case the FTC brought under the FACTA Disposal Rule (effective 2005), establishing that businesses handling consumer reports have an affirmative legal duty to destroy sensitive information before disposal, not merely to avoid mishandling it while in use, and that intact discarded documents in an accessible dumpster constitute a violation even absent proof of actual identity theft. It is widely cited in compliance and security-awareness training as the canonical "dumpster diving" enforcement precedent because the aggravating fact was recidivism: the company was formally warned in writing and continued the same unsafe disposal practice afterward, which regulators treated as evidence of an inadequate compliance program rather than an isolated mistake. It illustrates that physical document disposal is a data-security control subject to the same regulatory scrutiny as digital safeguards, and that consumer-facing financial companies face civil penalties for creating identity-theft risk through negligent physical security, independent of any confirmed attacker exploiting the exposure.

Defenses

The FTC's stipulated order required American United Mortgage to comply going forward with the Disposal Rule (burn, pulverize, or shred documents containing consumer report information, or take other reasonable measures so it cannot practicably be read or reconstructed), implement a comprehensive written GLBA Safeguards information-security program, provide GLBA Privacy Rule notices to customers, and undergo biennial independent third-party security audits for 10 years. More broadly the case is cited as the textbook justification for locked/secured disposal receptacles for documents containing SSNs, account numbers, or consumer report data; contracted shredding vendors with certificates of destruction; documented written disposal policies; and prompt remediation after any regulator or third-party warning (the aggravating factor here was that the company kept doing it after being formally notified).

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Target selection: Identity thieves who specialize in dumpster diving typically favor mortgage lenders and other financial-services firms as targets because loan origination requires collecting Social Security numbers, bank and credit-card account numbers, income data, and full consumer/credit reports on paper, in bulk.
Countering Stage 1: A financial-services firm cannot stop attackers from recognizing it as a high-value target simply because of the data it lawfully collects; the realistic control sits downstream, in how those records are protected and destroyed, not in denying the industry's data footprint.
2
Physical reconnaissance: Casing a target's premises to locate exterior trash receptacles, note whether they sit behind a fence, gate, or lock, and learn collection schedules is a low-cost, low-risk step commonly associated with dumpster-diving fraud, and one that an unsecured, publicly accessible dumpster near an office building would pass easily.
Countering Stage 2: Enclosing outdoor waste receptacles behind locked gates or fencing, and siting them away from public alley or street access, removes the easy visual reconnaissance and physical access that low-effort dumpster diving depends on.
3
Organizational failure creates and reopens the exposure window: per the FTC complaint, American United disposed of loan records by placing them, intact, in open trash bags rather than burning, pulverizing, or shredding them, and had no written GLBA Safeguards information-security program requiring otherwise. FTC staff found hundreds of such documents (including credit reports for 36 consumers) in February 2006, warned the company in writing in March 2006, and still found further discarded documents in the same unsecured dumpster on at least two later occasions, so the exposure window reopened repeatedly instead of closing after the warning.
Countering Stage 3: This is the control the case turned on. A documented, written GLBA Safeguards information-security program paired with FACTA Disposal Rule compliance (burning, pulverizing, or cross-cut shredding any document containing consumer report data before disposal) closes the organizational gap that let intact records accumulate again and again, even after a direct written warning from the regulator.
4
Document retrieval: With no shredding and no secured enclosure, anyone accessing the dumpster or surrounding trash bags could simply remove intact paperwork; no technical skill, intrusion, or deception of an employee was required.
Countering Stage 4: Locking disposal receptacles, or contracting a bonded shredding vendor that provides certificates of destruction (including on-site shredding for high-volume paper), removes the opportunity to retrieve intact documents from trash at all.
5
Data harvesting: Retrieved documents would let a person compile usable identity records (name, Social Security number, account numbers, credit history) from the consumer reports and loan files for later use.
Countering Stage 5: If documents are destroyed before disposal per Stage 3 and 4 controls, there is no intact PII left to harvest; this stage is preempted upstream rather than needing a separate control of its own.
6
Objective completion: The harvested data creates the conditions for identity theft or financial fraud enablement, for example fraudulent credit applications or account takeover using the exposed SSNs and account numbers. The public case record does not document any confirmed instance of this exploitation occurring; the FTC's Disposal Rule case treated the exposure itself, not proven downstream fraud, as the violation.
Countering Stage 6: Consumer-side protections such as credit freezes, fraud alerts, and account monitoring, plus lender-side fraud detection on new applications, reduce the damage if harvested identity data is ever used for fraud, though no such downstream exploitation was documented in this particular case.
Quick Facts
Victim
American United Mortgage Company (Northbrook, IL) as the regulated entity; its mortgage customers (at least 36 identified consumers whose credit reports were found discarded) as the at-risk data subjects
Location
Northbrook, Illinois, USA (case filed in the U.S. District Court for the Northern District of Illinois, Eastern Division)
Date
2006-02 (documents first discovered) to 2008-01-28 (final judgment entered); FTC complaint filed 2007-12-17/18
Impact
$50,000 civil penalty paid by American United Mortgage Company to the U.S. Treasury via the FTC/DOJ action; the case record does not document a specific dollar loss to consumers from identity theft or fraud attributable to the exposed documents.
Status
Confirmed
Case Type
Real-World Incident
Sector
Financial Services & Insurance
Related

Related Cases

Rite Aid Pharmacy Dumpster Disposal of Patient and Employee Records

TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels, patient records and job applications, leading…

Incident 2006Read →

Nations Title Agency / Nations Holding Company Dumpster Diving and Hack Exposure (FTC Settlement, 2006)

A Kansas City TV station found intact consumer home-loan applications with Social Security and account numbers tossed in a title…

Incident 2006Read →

Gen. Wesley Clark Phone Records Pretexting Incident (2005-2006)

A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…

Incident 2005Read →