A Kansas City TV station found intact consumer home-loan applications with Social Security and account numbers tossed in a title company's open dumpster, and combined with a 2004 website hack, it triggered an FTC settlement over failed data-security safeguards.
Reviewed by the Social Engineering Examples team.
Nations Title Agency (NTA) and its parent Nations Holding Company (NHC), a Kansas-based real estate/title-services conglomerate run by owner Christopher M. Likens, routinely handled sensitive consumer data, names, Social Security numbers, bank and credit card account numbers, mortgage/loan applications, purchase contracts, refinancing agreements, income and credit histories, in connection with home purchase financing, refinancing, closings, and related settlement services. According to the FTC's June 2006 complaint, since at least 2003 the companies failed to implement reasonable data-security safeguards. Two concrete incidents anchored the case: in April 2004, a hacker exploited a common website attack to gain unauthorized access to NHC's computer network; and in February 2005, a Kansas City television station, in the course of investigative reporting, found intact consumer documents, home loan applications containing Social Security numbers and account numbers, discarded in an open, unsecured dumpster adjacent to the companies' building. The FTC filed an administrative complaint and simultaneously announced a settlement on May 10, 2006 (FTC File No. 052 3117; Docket No. C-4161), with the Decision and Order issued June 19-20, 2006.
The case rested on a pattern of security failures the FTC said, taken together, left consumer data exposed both physically and online: the companies did not assess risks to information collected and stored (online or offline); lacked reasonable policies for employee screening/training and for the collection, handling, and disposal of personal information; failed to implement simple, low-cost defenses to common website attacks or reasonable access controls (e.g., strong passwords) to keep hackers off the network; failed to detect or respond to unauthorized access or investigate security incidents; and failed to oversee third-party service providers who handled personal information during closings. The physical-disposal failure meant loan files with SSNs and account numbers ended up intact in an outdoor dumpster with no destruction (shredding) or access control, where anyone, including reporters, could retrieve them. Separately, the companies' lax web-application and password security let a hacker use a routine, well-known attack technique to breach NHC's network. The FTC framed both as manifestations of the same root cause: no comprehensive, tested information-security program.
There was no social-engineering pretext aimed at an individual victim in this case; the exposure was structural. The 'tell' that surfaced the problem was purely physical and observational: an unsecured, open dumpster sitting next to the companies' Prairie Village office contained loan applications legible and intact enough for a Kansas City TV news crew to retrieve, film, and use as evidence that the company's public privacy-policy promises ('we maintain physical, electronic and procedural safeguards in compliance with federal standards to protect the information') were false. That gap between marketed privacy promises and actual disposal practice is what the FTC ultimately charged as a deceptive Section 5 violation, not merely a Safeguards Rule lapse.
The FTC and the respondents settled via consent order rather than litigation. Respondents did not admit liability; the consent agreement explicitly stated it was for settlement purposes only. The order: barred future misrepresentations about the extent of the companies' privacy/security protections; required establishment and maintenance of a comprehensive written information-security program with administrative, technical, and physical safeguards; required designation of responsible personnel, risk assessment, and ongoing testing/monitoring of safeguards; barred future violations of the GLBA Safeguards Rule (16 C.F.R. Part 314), Privacy Rule (16 C.F.R. Part 313), and the FTC's Disposal Rule (16 C.F.R. Part 682, effective June 1, 2005); required an initial assessment within 180 days and independent third-party professional assessments every two years for 20 years; imposed standard 5-10 year recordkeeping/document-retention obligations; and required Christopher Likens, for 10 years, to notify the FTC if he left his current business or entered any new financial-products/services business. No upfront civil penalty was assessed, though the order noted future violations could trigger civil penalties. This was, per then-FTC Chairman Deborah Platt Majoras, the agency's 'thirteenth case challenging faulty data security practices' at that point.
The case is a foundational example of 'dumpster diving' functioning as a compliance and reputational threat vector even without a named criminal exploiting it: a company's own discarded records, combined with a separate cyber intrusion, became the joint evidentiary basis for a federal enforcement action. It demonstrates that regulators (and journalists) treat improper physical disposal of financial/PII documents as equivalent in severity to a network breach, both stem from the same underlying failure to operationalize a real security program, and that a mismatch between a published privacy policy and actual practice ('safeguards' promised but not delivered) is independently actionable as a deceptive trade practice under FTC Act Section 5, on top of any sector-specific rule (GLBA Safeguards/Privacy/Disposal Rules).
Effective countermeasures illustrated (in the negative, by their absence here) include: cross-cut shredding or secure destruction of all documents containing PII/SSNs/account numbers before disposal, per the FTC's Disposal Rule; physically securing waste receptacles (locked, enclosed, access-controlled) so discarded paper isn't publicly retrievable; a written, tested information-security program with periodic risk assessments covering both physical and electronic data handling; basic web-application hardening and strong authentication to close 'common' attack vectors; monitoring/logging to detect unauthorized network access; and contractual oversight of third-party vendors who handle consumer data during transactions. The FTC's remedy, mandated recurring third-party security assessments for 20 years, reflects the view that a one-time fix is insufficient without ongoing verification.
TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels, patient records and job applications, leading…
CVS pharmacies nationwide tossed pill bottles, prescriptions, and employee SSNs into unsecured public dumpsters; media exposure across a dozen-plus cities…
The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports…