Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Thursday, January 13, 2011





Canada Enacts Anti-Spam, Phishing, Spyware Legislation

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

New Canadian anti-spam law legislation was approved by Parliament and received Royal Assent on December 15, 2010. The “Fighting Internet and Wireless Spam Act” (Statutes of Canada 2010, c. 23; Bill C-28) prohibits the sending of commercial electronic messages without the prior consent of the recipient. The legislation also addresses threats from other types of unsolicited electronic contact, including identity theft, phishing, spyware, viruses, and botnets.

The law grants a right of civil action to businesses and consumers targeted by the perpetrators of such activities. It will come into force on a day or days to be fixed by order of the Governor in Council.

Spam

Along with the prior consent requirement, the legislation provides that commercial e-mail messages must:

(1) Identify the person who sent the message and the person on whose behalf it is sent,

(2) Provide accurate contact information for these parties, and

(3) Set out an unsubscribe mechanism as outlined in the legislation.
The prohibition on spam does not apply to messages that facilitate, complete, or confirm a commercial transaction that has already been agreed to by the recipient, or that provides warranty, product recall, safety, or security information about a product, good, or service that the recipient has used or purchased.

Phishing

The same consent requirement for spam also applies to phishing messages. Phishing is described as e-mail that is sent from what appears to be an organization the recipient knows, such as a bank, requiring the recipient to send back personal information or confirm the information via a link.

Alterations of Transmissions

The legislation prohibits certain activities regarding electronic communications between two parties that have been intercepted. Such transmissions may not be altered so that the message is sent or copied anywhere other than where the sender thinks it is going.

All alterations to the transmission data require the express consent of the sender, with the ability to withdraw that consent at will. Service providers are exempt from this requirement, because they sometimes need to alter transmission data for technical reasons.

Unauthorized Software

The statute provides that no one may, in the course of a commercial activity, install or cause to be installed a computer program on any other person’s computer system, nor may anyone use any installed program to cause an electronic message to be sent from another person’s computer, without the owner’s express consent. This provision is aimed particularly at the surreptitious installation of spyware and malware.

Enforcement and Penalties

The law designates the Canadian Radio-television and Telecommunications Commission as the main regulatory agency responsible for pursuing administrative penalties against violators. The CRTC is given investigative powers by the statute, including the power to require production of documents.

The maximum penalty for an individual is $1 million and the maximum penalty for a corporation or other organization is $10 million. These penalties are to be imposed per violation.

The law also amends the Personal Information Protection and Electronic Documents Act (CCH Privacy Law in Marketing ¶42,200) to expand the Privacy Commissioner’s discretion and permit the Office of the Privacy Commissioner to take measures against the unauthorized collection of personal information through hacking or illicit trading of lists of electronic addresses.

In addition, the law amends the Competition Act, giving the Competition Bureau and the Commissioner of Competition a role in investigating and enforcing the new anti-spam provisions. Under the anti-spam legislation, the Competition Act’s existing regime on misleading and deceptive practices has been expanded to include online activity.

Private Right of Action

Persons affected by violations are able to bring a private action for actual damages. Courts may also award statutory damages of $200 for each violation, up to a maximum of $1 million per day.

Text of the legislation will appear in CCH Privacy Law in Marketing. More information on the law is available here at the Canadian Parliament’s website.

Monday, April 12, 2010





Utah Enacts Phishing, Pharming, Spyware Prohibitions

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

The new Utah “E-Commerce Integrity Act,” which was signed by Governor Gary R. Herbert on March 26, 2010, prohibits certain Internet-related conduct, including phishing and pharming. The law (Senate Bill 26) also repeals Utah’s “Spyware Control Act” and enacts new restrictions on the use of spyware.

“Phishing” is defined by the law as making a communication under false pretenses purporting to be by or on behalf of a legitimate business and using that communication to induce another person to provide identification information or property.

“Pharming” is described as the creation or operation of a website that falsely represents itself to be associated with a legitimate business and that induces others to provide identifying information or property. The statute prohibits the use of spyware to collect, through intentionally deceptive means, personally identifiable information.

Civil Action, Remedies

A civil action may be brought against violators of the phishing and pharming provisions by an Internet service provider that is adversely affected by the violation; an owner of a website, computer server, or a trademark that is used without authorization in the violation; or the state attorney general. Remedies include actual damages or a civil penalty of up to $150,000 per violation.

Civil actions to enforce the law’s spyware provisions may be brought by the state attorney general, an Internet service provider, or a software company that expends resources in good faith to assist authorized users harmed by a violation, as well as a trademark owner whose mark is used to deceive authorized users.

Damages, Fees, Costs

Plaintiffs may seek actual damages and liquidated damages of at least $1,000 per violation, not to exceed $1 million for a pattern or practice of violations, and attorney’s fees and costs. Courts are authorized to award treble damages for willful and knowing violations.

Utah’s “E-Commerce Integrity Act” will take effect on July 1, 2010. Text of the law appears at CCH Privacy Law in Marketing ¶34,442.

Thursday, May 07, 2009





Privacy Laws Proposed in Congress, Canadian Parliament

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Federal laws addressing privacy concerns have been introduced recently in both Congress and Canada’s Parliament.

Data Security, Breach Notification

The Congressional proposal would regulate information security standards and breach notification procedures. The proposed “Data Accountability and Trust Act” (H.R. 2221) would require persons engaged in interstate commerce that own or possess data in electronic form containing personal information—or that contract to have a third-party maintain such data—to establish and implement reasonable security policies and procedures to protect that data. The measure would also provide for nationwide notice in the event of a security breach.

The proposed law would be enforced by the Federal Trade Commission and state attorneys general. A private right of action would not be available, and the federal statute would preempt state data security and breach notification laws and regulations.

The bill, introduced April 30, was sponsored by Rep. Bobby Rush (D-Ill.) and co-sponsored by Reps. Cliff Stearns (R-Fla.), Joe Barton (R-Tex.), Jan Schakowsky (D-Ill.), and George Radanovich (R-Calif.). Further information—and text of the bill—appears at the Thomas site of the Library of Congress.

Spam, Phishing

The Canadian legislation is aimed at deterring “the most dangerous forms of spam” and threats posed to privacy and personal security by Internet fraud.

The proposed “Electronic Commerce Protection Act” (ECPA) would prohibit the sending of commercial electronic messages without the prior consent of the recipient and would provide rules regulating the sending of such messages, including a mechanism for withdrawal of consent. It would also prohibit the alternation of e-commerce data transmissions and the unauthorized installation of computer addresses.

Persons injured by violations would have a private right of action for actual and statutory damages. The Canadian Radio-television and Telecommunications Commission and the Competition Bureau would also be authorized to impose administrative monetary penalties of up to $1 million Canadian for individuals and $10 million Canadian for all other offenders.

The proposal (Bill C-27) was introduced in the House of Commons of Canada on April 24. Text of the bill is available here.

Monday, April 13, 2009





Facebook Obtains Order Barring Phishing, Spamming Scheme

This posting was written by Cheryl Beise, Editor of CCH Guide to Computer Law, and Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Social networking website operator Facebook, Inc. was entitled to an ex parte temporary restraining order against Internet marketers that allegedly used Facebook's website to engage in a phishing and spamming scheme, in violation of the CAN-SPAM Act, the Computer Fraud and Abuse Act, and California law, the federal district court in San Jose has determined. Facebook asserted that the scheme compromised the accounts of a substantial number of Facebook users.

The marketers allegedly sent out seemingly legitimate e-mails to multiple Facebook users, asking them to click on a link, which led to a phishing site designed to trick users into divulging their Facebook login information. The marketers then allegedly used the information to send spam to the users' "friends." As the cycle was repeated, the number of compromised Facebook accounts increased exponentially.

A TRO was warranted because of the strong possibility of irreparable injury to Facebook's reputation and to the personal privacy of Facebook users, the court said.

The balance of hardships clearly favored Facebook because it was required to expend significant time and resources to combat the marketer's activities. The marketers would suffer little or no hardship if enjoined from conducting their allegedly illegal scheme.

The order granting a temporary restraining order is Facebook, Inc. v. Wallace, CCH Guide to Computer Law ¶49,699 and CCH Privacy Law in Marketing ¶60,308.