AT&T Pays to Settle Customer Information Investigation

According to a July 19 article in TechWeb Technology News, AT&T has agreed to pay a $550,000 settlement on behalf of recently acquired SBC to end an investigation into third-party access to customer telephone records.

The article is reprinted below —

AT&T will pay a $550,000 settlement to end an investigation into third-party access to information about customers’ telephone calls.

The company recently agreed to pay the money on behalf of recently-acquired SBC. Both companies cooperated with the enforcement bureau of the Federal Communications Commission during an investigation into whether customer confidentiality was breached. The payment, due within 30 days, does not constitute an admission of wrongdoing, according to language in the agreement.

The company agreed to supervision and review of its opt-out processes for releasing proprietary customer network information (CPNI). The company also agreed to monitor customer complaints and identify violations of the FCC’s opt-out rules.

The Electronic Privacy Information Center prompted the investigation when it submitted a petition to the FCC in August 2005. EPIC argued for strengthened security and authentication standards for accessing customer phone records, including call histories, subscribers’ unlisted phone numbers and other personal information obtained by online information brokers.

In the petition, EPIC pointed out that online brokers advertise their ability to obtain the information without account holders’ knowledge and consent, that the information is gained in hours (indicating it could not have been obtained legally) and that carriers aren’t careful enough about validating the identity of the person requesting the information. EPIC suggested that carriers were not doing their part to prevent pretexting, the practice of assuming an identity to obtain personal information from an account holder.