The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports and financial records in an unsecured dumpster, kept doing it even after a written FTC warning, and paid a $50,000 penalty.
Reviewed by the Social Engineering Examples team.
American United Mortgage Company, a mortgage lender headquartered in Northbrook, Illinois, was the subject of the Federal Trade Commission's first-ever enforcement action under the FACTA Disposal Rule. In February 2006, hundreds of loan-related documents containing consumers' sensitive personal and financial information, including full consumer/credit reports for 36 identifiable consumers, Social Security numbers, and bank/credit-card account numbers, were found discarded in open trash bags in and around an unsecured dumpster near the company's office. FTC staff notified the company in writing in March 2006 that this violated federal disposal requirements, but improperly discarded consumer documents were found in the same unsecured dumpster on at least two further occasions afterward. The FTC's complaint, filed by the Department of Justice on its behalf in the U.S. District Court for the Northern District of Illinois (Civil Action No. 07C 7064) on December 17-18, 2007, alleged violations of the FACTA/FCRA Disposal Rule, the Gramm-Leach-Bliley Act Safeguards Rule (no written information-security program), and the GLBA Privacy Rule (no privacy notices to customers from July 2001 through March 2006). A stipulated final judgment entered January 28, 2008 imposed a $50,000 civil penalty and ongoing compliance and audit requirements.
American United Mortgage, a mortgage lender that collected sensitive consumer data (Social Security numbers, bank and credit-card account numbers, income information, credit histories, and full consumer/credit reports) as part of loan origination, disposed of paper records by placing them in open trash bags in and around a dumpster near its office that was not secured against public access. There was no shredding, pulverizing, or other destruction step before disposal, so intact documents containing consumer report data were left exposed to anyone who accessed the dumpster or surrounding trash. The FTC also alleged the company had no comprehensive written information-security program (GLBA Safeguards Rule) and, from July 1, 2001 through March 2006, failed to give customers the privacy notices required under the GLBA Privacy Rule, meaning the disposal failure sat inside a broader pattern of absent data-handling controls rather than a single one-off lapse.
There was no deceptive "lure" aimed at a human victim in this case; it is a passive-exposure incident, not a social-engineering pretext. Detection came in February 2006, when hundreds of documents were found discarded in open trash bags near the company's dumpster, including consumer (credit) reports for 36 identifiable consumers. FTC staff sent American United a written warning in March 2006 specifically telling the company to fix its disposal practices. Despite that formal notice, FTC investigators (or their sources) found additional improperly discarded consumer documents in the same unsecured dumpster on at least two subsequent occasions. The repeated recurrence after an explicit warning was the key aggravating fact the FTC cited in seeking penalties rather than a warning letter alone.
The U.S. Department of Justice, at the FTC's request, filed a complaint for civil penalties, injunctive and other relief against American United Mortgage Company in the U.S. District Court for the Northern District of Illinois, Eastern Division (Civil Action No. 07C 7064 / docketed as 1:07-cv-07064) on December 17-18, 2007. A stipulated final judgment and order was entered January 28, 2008, imposing a $50,000 civil penalty, a permanent injunction against further violations of the Disposal, Safeguards, and Privacy Rules, and a requirement to obtain independent third-party security audits every two years for 10 years. No criminal charges were brought and no identity-theft victims or fraud losses tied to the exposed documents were identified in the public case record; this was a civil regulatory enforcement action, not a prosecution of an attacker.
This was the first case the FTC brought under the FACTA Disposal Rule (effective 2005), establishing that businesses handling consumer reports have an affirmative legal duty to destroy sensitive information before disposal, not merely to avoid mishandling it while in use, and that intact discarded documents in an accessible dumpster constitute a violation even absent proof of actual identity theft. It is widely cited in compliance and security-awareness training as the canonical "dumpster diving" enforcement precedent because the aggravating fact was recidivism: the company was formally warned in writing and continued the same unsafe disposal practice afterward, which regulators treated as evidence of an inadequate compliance program rather than an isolated mistake. It illustrates that physical document disposal is a data-security control subject to the same regulatory scrutiny as digital safeguards, and that consumer-facing financial companies face civil penalties for creating identity-theft risk through negligent physical security, independent of any confirmed attacker exploiting the exposure.
The FTC's stipulated order required American United Mortgage to comply going forward with the Disposal Rule (burn, pulverize, or shred documents containing consumer report information, or take other reasonable measures so it cannot practicably be read or reconstructed), implement a comprehensive written GLBA Safeguards information-security program, provide GLBA Privacy Rule notices to customers, and undergo biennial independent third-party security audits for 10 years. More broadly the case is cited as the textbook justification for locked/secured disposal receptacles for documents containing SSNs, account numbers, or consumer report data; contracted shredding vendors with certificates of destruction; documented written disposal policies; and prompt remediation after any regulator or third-party warning (the aggravating factor here was that the company kept doing it after being formally notified).
TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels, patient records and job applications, leading…
A Kansas City TV station found intact consumer home-loan applications with Social Security and account numbers tossed in a title…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…