A Kansas City TV station found intact consumer home-loan applications with Social Security and account numbers tossed in a title company's open dumpster.
Social Engineering Examples·5 sources
Nations Title Agency (NTA) and its parent Nations Holding Company (NHC), a Kansas-based real estate/title-services conglomerate run by owner Christopher M. Likens, routinely handled sensitive consumer data, names, Social Security numbers, bank and credit card account numbers, mortgage/loan applications, purchase contracts, refinancing agreements, income and credit histories, in connection with home purchase financing, refinancing, closings, and related settlement services.
According to the FTC's June 2006 complaint, since at least 2003 the companies failed to implement reasonable data-security safeguards. Two concrete incidents anchored the case: in April 2004, a hacker exploited a common website attack to gain unauthorized access to NHC's computer network; and in February 2005, a Kansas City television station, in the course of investigative reporting, found intact consumer documents, home loan applications containing Social Security numbers and account numbers, discarded in an open, unsecured dumpster adjacent to the companies' building.
The FTC filed an administrative complaint and simultaneously announced a settlement on May 10, 2006 (FTC File No. 052 3117; Docket No. C-4161), with the Decision and Order issued June 19-20, 2006.
The case rested on a pattern of security failures the FTC said, taken together, left consumer data exposed both physically and online: the companies did not assess risks to information collected and stored (online or offline); lacked reasonable policies for employee screening/training and for the collection, handling, and disposal of personal information; failed to implement simple, low-cost defenses to common website attacks or reasonable access controls (e.g., strong passwords) to keep hackers off the network; failed to detect or respond to unauthorized access or investigate security incidents; and failed to oversee third-party service providers who handled personal information during closings.
The physical-disposal failure meant loan files with SSNs and account numbers ended up intact in an outdoor dumpster with no destruction (shredding) or access control, where anyone, including reporters, could retrieve them. Separately, the companies' lax web-application and password security let a hacker use a routine, well-known attack technique to breach NHC's network.
The FTC framed both as manifestations of the same root cause: no comprehensive, tested information-security program.
There was no social-engineering pretext aimed at an individual victim in this case; the exposure was structural. The 'tell' that surfaced the problem was purely physical and observational: an unsecured, open dumpster sitting next to the companies' Prairie Village office contained loan applications legible and intact enough for a Kansas City TV news crew to retrieve, film, and use as evidence that the company's public privacy-policy promises ('we maintain physical, electronic and procedural safeguards in compliance with federal standards to protect the information') were false.
That gap between marketed privacy promises and actual disposal practice is what the FTC ultimately charged as a deceptive Section 5 violation, not merely a Safeguards Rule lapse.
The FTC and the respondents settled via consent order rather than litigation. Respondents did not admit liability; the consent agreement explicitly stated it was for settlement purposes only. The order: barred future misrepresentations about the extent of the companies' privacy/security protections; required establishment and maintenance of a comprehensive written information-security program with administrative, technical, and physical safeguards; required designation of responsible personnel, risk assessment, and ongoing testing/monitoring of safeguards; barred future violations of the GLBA Safeguards Rule (16 C.F.R. Part 314), Privacy Rule (16 C.F.R. Part 313), and the FTC's Disposal Rule (16 C.F.R. Part 682, effective June 1, 2005); required an initial assessment within 180 days and independent third-party professional assessments every two years for 20 years; imposed standard 5-10 year recordkeeping/document-retention obligations; and required Christopher Likens, for 10 years, to notify the FTC if he left his current business or entered any new financial-products/services business.
No upfront civil penalty was assessed, though the order noted future violations could trigger civil penalties. This was, per then-FTC Chairman Deborah Platt Majoras, the agency's 'thirteenth case challenging faulty data security practices' at that point.
The case is a foundational example of 'dumpster diving' functioning as a compliance and reputational threat vector even without a named criminal exploiting it: a company's own discarded records, combined with a separate cyber intrusion, became the joint evidentiary basis for a federal enforcement action. It demonstrates that regulators (and journalists) treat improper physical disposal of financial/PII documents as equivalent in severity to a network breach, both stem from the same underlying failure to operationalize a real security program, and that a mismatch between a published privacy policy and actual practice ('safeguards' promised but not delivered) is independently actionable as a deceptive trade practice under FTC Act Section 5, on top of any sector-specific rule (GLBA Safeguards/Privacy/Disposal Rules).
Effective countermeasures illustrated (in the negative, by their absence here) include: cross-cut shredding or secure destruction of all documents containing PII/SSNs/account numbers before disposal, per the FTC's Disposal Rule; physically securing waste receptacles (locked, enclosed, access-controlled) so discarded paper isn't publicly retrievable; a written, tested information-security program with periodic risk assessments covering both physical and electronic data handling; basic web-application hardening and strong authentication to close 'common' attack vectors; monitoring/logging to detect unauthorized network access; and contractual oversight of third-party vendors who handle consumer data during transactions.
The FTC's remedy, mandated recurring third-party security assessments for 20 years, reflects the view that a one-time fix is insufficient without ongoing verification.
Social Engineering Examples. “Nations Title Agency / Nations Holding Company Dumpster Diving and Hack Exposure (FTC Settlement, 2006)”. Accessed 19 September 2026. https://socialengineeringexamples.com/nations-title-agency-dumpster-diving-ftc-2006
Per the FTC complaint, since at least 2003 the companies never assessed risks to the personal information they held online or offline and had no written information-security program, leaving both their paper records and their computer network without any documented safeguards for roughly a year or more before either incident occurred.
A documented, periodically-tested risk assessment covering both online and offline handling of personal information, the exact program the FTC later mandated for 20 years, closes this stage before either downstream failure can develop.
The companies had no reasonable policy for the collection, handling, or disposal of personal information, so intact home-loan applications carrying Social Security numbers and account numbers were routinely thrown out whole rather than shredded or otherwise destroyed.
A written retention-and-destruction policy requiring cross-cut shredding or other secure destruction of any document containing Social Security or account numbers before disposal, consistent with the FTC's Disposal Rule (16 C.F.R. Part 682), stops intact records from ever reaching the trash.
The companies also failed to implement simple, low-cost defenses against common website attacks or reasonable access controls such as strong passwords, leaving NHC's computer network exploitable through well-known attack techniques.
Routine web-application patching against known attack classes plus enforced strong-password and access-control policies on networks storing consumer personal information, as required under the GLBA Safeguards Rule, removes the low-cost attack path the hacker used.
In April 2004, an unidentified hacker used one of these common website attack techniques to gain unauthorized access to NHC's computer network; the FTC complaint does not describe what, if anything, the hacker did with that access, and the companies had no monitoring or incident-response capability to detect or investigate the intrusion.
Network monitoring, logging, and intrusion detection paired with a defined incident-response process would let a company notice and investigate unauthorized access instead of having no visibility into it at all, which the complaint specifically flagged as missing.
Discarded loan files sat intact, legible, and unsecured in an open dumpster adjacent to the companies' Prairie Village office for an unknown period, retrievable by anyone who walked by, with no locked enclosure or destruction step to stop it.
Locked, enclosed, access-controlled waste receptacles for any area handling consumer PII remove the window in which discarded originals sit publicly retrievable, independent of whether the destruction step at Stage 2 is followed consistently.
In February 2005, a Kansas City television station's investigative reporters found, retrieved, and filmed the discarded documents, exposing the gap between the companies' published privacy-policy promise of 'physical, electronic and procedural safeguards' and their actual practice.
There is no practical control against a journalist or member of the public who finds records already sitting exposed. Once Stage 2 or Stage 5 controls are actually in place there is nothing intact left to discover, so the real fix sits upstream in disposal practice rather than in preventing exposure from being noticed.
The televised exposure fed into an FTC investigation and administrative complaint; because no financial fraud or identity-theft loss was documented in the case record, the realized consequence for the companies was reputational and regulatory, a consent order imposing a mandated security program, 20 years of biennial third-party audits, and personal notification duties for owner Christopher Likens, rather than a direct financial payout to any attacker.
Keeping public privacy-policy claims accurate and backed by an operating, independently audited security program avoids compounding a security failure with a separate deceptive-practices finding under FTC Act Section 5, and having the program already documented and tested reduces both the odds of enforcement and its severity if it happens anyway.
Browse by what this case has in common with others in the library.
TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels.
CVS pharmacies nationwide tossed pill bottles, prescriptions, and employee SSNs into unsecured public dumpsters.
The FTC's first-ever case under the FACTA Disposal Rule: a Northbrook, Illinois mortgage lender repeatedly dumped intact customer credit reports.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
A mass-phishing malware infection at Target's small HVAC contractor harvested vendor-portal credentials that attackers reused to pivot.
A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136…
A Bengaluru retiree lost Rs 6.88 lakh after an AI-generated deepfake Facebook video falsely showed Finance Minister Nirmala Sitharaman endorsing…
The FBI's 2025 Internet Crime Report introduced its first dedicated AI-fraud tracking category, logging $893 million in losses.
The Crelan Bank phishing attack: fraudsters impersonating the CEO tricked staff into wiring nearly €70M (~$75.8M) in Belgium's costliest CEO…
A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M…
Between 2006 and 2008 the FTC sued 16 data-broker and private-investigation defendants who pretexted telecom carriers.
FTC's December 2024 Data Spotlight quantified an explosion in "task scams," gamified job-offer frauds launched via unsolicited text/WhatsApp messages.
A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136…
A Chicago hairstylist wired $20,000 of her own money to scammers after a caller impersonating Bank of America.
Scammers papered roughly 200 counterfeit QR-code stickers over legitimate ParkMobile decals on downtown Orlando parking meters.
A Pennsylvania shredding-business owner's 2010 qui tam suit alleged that Shred-It, Iron Mountain.