MoviePass settles with the FTC over exposing private information, misleading consumers
Full article592 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The FTC also slammed the company for using an array of tricks to keep users from actually using the service.
Defunct subscription service MoviePass won’t have to pay users for exposing their personal information, or for quietly blocking them from using the movie ticket service’s “one ticket per day” feature.
The now-bankrupt company settled with the Federal Trade Commission Tuesday over allegations that it failed to secure users’ personal information and misled them about the company’s subscription offerings, the agency announced.
The subscription service, which launched in 2011, once attracted more than 3 million paid subscribers for its unrivaled service of offering unlimited movie theater passes for initially just $9.99 a month. The business model turned out to be unsustainable, with the company turning to increased prices and eventually bankruptcy in January 2020 after struggling to retain subscribers.
Failure to secure a server of users’ private information led to the exposure of tens of thousands of names, birthdates, customer card numbers and credit card numbers between at least May and August of 2019, TechCrunch reported at the time. The company’s privacy policy said it encrypted customers payment information but the information in the server was unencrypted.
“The company didn’t even take basic steps to secure sensitive information, and its systems were breached,” FTC Commissioner Rohit Chopra tweeted.
The FTC also slammed the company for using an array of tricks to keep users from actually using the service. The company allegedly issued misleading notices about password disruptions and flagged unsubstantiated suspicious activity and potential fraud to invalidate user passwords.
The company also instituted measures to quietly block users from seeing more than three movies per month despite promising consumers one movie per day.
“MoviePass and its executives went to great lengths to deny consumers access to the service they paid for while also failing to secure their personal information,” Daniel Kaufman, the FTC’s acting director of the Bureau of Consumer Protection, said in a press release.
The FTC will not provide restitution since the settlement comes after the company went bankrupt. The proposed consent order requires parent company Helios and Matheson Analytics, Inc. and principal executives Mitchell Lowe and Theodore Farnsworth to enact “comprehensive information security programs” for future businesses and report any data breaches.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/moviepass-password-ftc-settlement-price/