<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Identity Theft | Interactive News</title>
	<atom:link href="https://111things.com/tag/identity-theft/feed/" rel="self" type="application/rss+xml" />
	<link>https://111things.com</link>
	<description>Ask follow up questions &#38; get instant answers and insights.</description>
	<lastBuildDate>Fri, 28 Aug 2026 12:07:17 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://i0.wp.com/111things.com/wp-content/uploads/2026/06/111things-apple-touch-icon-180-1.png?fit=32%2C32&#038;ssl=1</url>
	<title>Identity Theft | Interactive News</title>
	<link>https://111things.com</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">126483067</site>        <div class="get111-archive-chat" data-get111-context="tag" data-get111-bot="default" data-get111-autosend="1" data-get111-term="identity-theft" data-get111-term-name="Identity Theft">
            <div class="get111-archive-chatbot">
                <div class='mwai-chatbot-container' data-params='{&quot;customId&quot;:&quot;get111-archive-tag-default&quot;,&quot;aiName&quot;:&quot;The 111: &quot;,&quot;userName&quot;:&quot;User:&quot;,&quot;guestName&quot;:&quot;Guest:&quot;,&quot;textSend&quot;:&quot;Send&quot;,&quot;textClear&quot;:&quot;Clear&quot;,&quot;imageUpload&quot;:false,&quot;fileUpload&quot;:false,&quot;multiUpload&quot;:false,&quot;maxUploads&quot;:1,&quot;fileUploads&quot;:0,&quot;mode&quot;:&quot;chat&quot;,&quot;textInputPlaceholder&quot;:&quot;Ask me anything&quot;,&quot;textInputMaxLength&quot;:12000,&quot;textCompliance&quot;:&quot; &quot;,&quot;startSentence&quot;:&quot;&quot;,&quot;localMemory&quot;:true,&quot;themeId&quot;:&quot;foundation&quot;,&quot;window&quot;:false,&quot;icon&quot;:&quot;&quot;,&quot;iconText&quot;:&quot;&quot;,&quot;iconTextDelay&quot;:1,&quot;iconAlt&quot;:&quot;AI Engine Chatbot&quot;,&quot;iconPosition&quot;:&quot;bottom-right&quot;,&quot;centerOpen&quot;:false,&quot;width&quot;:&quot;&quot;,&quot;openDelay&quot;:&quot;&quot;,&quot;iconBubble&quot;:false,&quot;windowAnimation&quot;:&quot;zoom&quot;,&quot;fullscreen&quot;:false,&quot;copyButton&quot;:false,&quot;pdfButton&quot;:false,&quot;headerSubtitle&quot;:&quot;Discuss with&quot;,&quot;containerType&quot;:&quot;standard&quot;,&quot;headerType&quot;:&quot;standard&quot;,&quot;messagesType&quot;:&quot;standard&quot;,&quot;inputType&quot;:&quot;standard&quot;,&quot;footerType&quot;:&quot;standard&quot;}' data-system='{&quot;botId&quot;:null,&quot;customId&quot;:&quot;get111-archive-tag-default&quot;,&quot;userData&quot;:null,&quot;sessionId&quot;:null,&quot;restNonce&quot;:null,&quot;contextId&quot;:null,&quot;pluginUrl&quot;:&quot;https:\/\/111things.com\/wp-content\/plugins\/ai-engine-pro&quot;,&quot;restUrl&quot;:&quot;https:\/\/111things.com\/wp-json&quot;,&quot;stream&quot;:true,&quot;debugMode&quot;:true,&quot;eventLogs&quot;:false,&quot;speech_recognition&quot;:false,&quot;speech_synthesis&quot;:false,&quot;typewriter&quot;:false,&quot;crossSite&quot;:false,&quot;actions&quot;:[],&quot;blocks&quot;:[],&quot;shortcuts&quot;:[]}' data-theme='{&quot;type&quot;:&quot;internal&quot;,&quot;name&quot;:&quot;Foundation&quot;,&quot;themeId&quot;:&quot;foundation&quot;,&quot;settings&quot;:[],&quot;style&quot;:&quot;&quot;,&quot;cssUrl&quot;:&quot;https:\/\/111things.com\/wp-content\/plugins\/ai-engine-pro\/themes\/foundation.css&quot;}'></div>            </div>

            <div class="get111-quicklinks" aria-label="Quick questions about Identity Theft">
                                                        <button type="button" class="get111-quicklink" data-label="Local Snapshot" data-ask="Give me a quick local snapshot of Identity Theft: what it&#039;s known for, neighborhoods, and vibe.">
                        Local Snapshot                    </button>
                                                        <button type="button" class="get111-quicklink" data-label="Housing Snapshot" data-ask="Give me a housing snapshot for Identity Theft: typical rent, home prices, and neighborhood differences.">
                        Housing Snapshot                    </button>
                                                        <button type="button" class="get111-quicklink" data-label="Education &amp; Income" data-ask="Summarize education levels, incomes, and major employers in Identity Theft.">
                        Education &amp; Income                    </button>
                                                        <button type="button" class="get111-quicklink" data-label="Economy &amp; Work" data-ask="Give me an economy breakdown for Identity Theft: top industries, major employers, and job trends.">
                        Economy &amp; Work                    </button>
                                                        <button type="button" class="get111-quicklink" data-label="Growth &amp; Pulse" data-ask="What&#039;s the growth &amp; momentum story in Identity Theft? New development, in-/out-migration, business growth, and what&#039;s changing.">
                        Growth &amp; Pulse                    </button>
                                                        <button type="button" class="get111-quicklink" data-label="Health &amp; Lifestyle" data-ask="Summarize health, lifestyle, and what locals do for fun in Identity Theft.">
                        Health &amp; Lifestyle                    </button>
                                                        <button type="button" class="get111-quicklink" data-label="Climate &amp; Risk" data-ask="Summarize climate patterns and practical risks in Identity Theft (storms, heat, flooding, etc.).">
                        Climate &amp; Risk                    </button>
                                                        <button type="button" class="get111-quicklink" data-label="Services Mix" data-ask="List common local services people look for in Identity Theft (insurance, finance, legal, home services, etc.).">
                        Services Mix                    </button>
                            </div>
        </div>
        	<item>
		<title>CareCloud breach estimate rises to 3.75 million people</title>
		<link>https://111things.com/national/carecloud-breach-estimate-rises-to-3-75-million-people/</link>
					<comments>https://111things.com/national/carecloud-breach-estimate-rises-to-3-75-million-people/#respond</comments>
		
		<dc:creator><![CDATA[Brian Bateman]]></dc:creator>
		<pubDate>Fri, 28 Aug 2026 12:07:17 +0000</pubDate>
				<category><![CDATA[National]]></category>
		<category><![CDATA[Consumer Protection]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Healthcare]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[United States]]></category>
		<guid isPermaLink="false">https://111things.com/?p=948047</guid>

					<description><![CDATA[HHS lists 3,756,469 people affected in the CareCloud breach, far above earlier notices. Here is what the revised count means and what consumers should do.]]></description>
										<content:encoded><![CDATA[<p>The number of people listed as affected in the CareCloud healthcare-data breach has risen to 3,756,469, far above the roughly 345,000 to 350,000 people identified in earlier notices and reports.</p>
<p>The revised figure appears in the U.S. Department of Health and Human Services Office for Civil Rights breach portal. <a href="https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf" rel="nofollow noopener" target="_blank">HHS</a> lists CareCloud, Inc., as a New Jersey business associate reporting a hacking or information-technology incident. The breach submission date shown in the federal record is July 24, 2026.</p>
<p>For people who received an earlier CareCloud notice, the updated figure means the first estimate should not be assumed to represent the final scope. The HHS number is an affected-population count. It does not establish that every person had an entire medical record stolen or that the same information was exposed for everyone.</p>
<h2>Why the CareCloud count changed</h2>
<p>Earlier state disclosures and reporting put the potentially affected population at approximately 345,000 to 350,000 people. Independent reporting in August described the later federal total as roughly 3.75 million.</p>
<p>CareCloud provides electronic-record and healthcare technology services to providers across the United States. Because the company supports providers in multiple states, the incident is not necessarily limited to New Jersey residents, even though HHS lists the company in New Jersey.</p>
<h2>What happened in March</h2>
<p>CareCloud’s March 24 Form 8-K said the company discovered a temporary network disruption on March 16. The disruption affected functionality and data access in one of six electronic health record environments for approximately eight hours before service was restored.</p>
<p>In that initial filing, CareCloud said it was still determining whether information had been accessed or exfiltrated. The company’s later Form 10-Q said unauthorized access began approximately one week before the March 16 discovery and that subsequent forensic analysis indicated an undetermined amount of data was exfiltrated.</p>
<p>State disclosures and independent reporting describe access to an AWS-hosted or cloud-supported patient-data environment during approximately March 10 through March 16. CareCloud said the incident was contained and that it believed the threat actor no longer had access. That remains the company’s assessment, not an independent finding.</p>
<h2>What information may be involved</h2>
<p>Independent reports and breach notifications have described potentially exposed information including names, postal addresses, Social Security numbers, government-issued identification numbers, bank-account or payment-card information, and medical or health information.</p>
<p>The combination of health information with identity and financial details can create long-term risks. Those include identity theft, medical identity theft, insurance fraud and targeted phishing that uses personal healthcare details to appear credible.</p>
<h2>What affected people should do now</h2>
<ul>
<li><strong>Verify communications independently.</strong> Do not use links or phone numbers in a suspicious email, text or letter. Contact CareCloud or the relevant healthcare provider through a trusted website, statement or previously known number.</li>
<li><strong>Review credit activity.</strong> Check credit reports and account statements for unfamiliar activity. Consider placing a fraud alert or credit freeze with the major credit bureaus.</li>
<li><strong>Watch medical records and insurance statements.</strong> Look for unfamiliar services, prescriptions or insurance claims.</li>
<li><strong>Secure reused passwords.</strong> Change passwords reused on affected accounts and enable multifactor authentication where available.</li>
<li><strong>Keep documentation.</strong> Save breach notices, account records and correspondence. They may help with disputes, identity-theft reports or future claims.</li>
</ul>
<p>The Federal Trade Commission directs consumers affected by data breaches to monitor accounts, consider credit protections and use federal identity-theft recovery resources if misuse appears.</p>
<h2>What remains unknown</h2>
<p>The public filings do not establish the exact amount or categories of data exfiltrated for each person. CareCloud’s Form 10-Q also says the company has been served with two patient class-action complaints and anticipates possible additional complaints. Those are company-reported legal matters, not adjudicated findings of wrongdoing.</p>
<p>The investigation and notification process may continue. People who received an earlier notice should follow updates from HHS, the <a href="https://www.ftc.gov/data-breach-resources" rel="nofollow noopener" target="_blank">FTC</a>, CareCloud and their healthcare providers rather than treating the original estimate as final.</p>
<h2>Sources</h2>
<ul>
<li><a href="https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf" rel="nofollow noopener" target="_blank">HHS Office for Civil Rights Breach Portal</a></li>
<li><a href="https://www.sec.gov/Archives/edgar/data/1582982/000149315226013239/form8-k.htm" rel="nofollow noopener" target="_blank">CareCloud Form 8-K</a></li>
<li><a href="https://www.itpro.com/security/data-breaches/data-belonging-to-3-75-million-patients-was-exposed-in-the-carecloud-breach-not-the-350-000-originally-reported" rel="nofollow noopener" target="_blank">IT Pro: CareCloud breach estimate revised</a></li>
<li><a href="https://www.ftc.gov/data-breach-resources" rel="nofollow noopener" target="_blank">Federal Trade Commission data-breach resources</a></li>
</ul>
]]></content:encoded>
					
					<wfw:commentRss>https://111things.com/national/carecloud-breach-estimate-rises-to-3-75-million-people/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">948047</post-id>	</item>
		<item>
		<title>Healthcare software breach may expose data of 3.8 million people</title>
		<link>https://111things.com/national/healthcare-software-breach-may-expose-data-of-3-8-million-people/</link>
					<comments>https://111things.com/national/healthcare-software-breach-may-expose-data-of-3-8-million-people/#respond</comments>
		
		<dc:creator><![CDATA[Brian Bateman]]></dc:creator>
		<pubDate>Fri, 14 Aug 2026 23:57:24 +0000</pubDate>
				<category><![CDATA[National]]></category>
		<category><![CDATA[Consumer Protection]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Healthcare]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[United States]]></category>
		<guid isPermaLink="false">https://111things.com/?p=947165</guid>

					<description><![CDATA[Patients are receiving notices after a healthcare software vendor said an October 2025 intrusion may have exposed sensitive information nationwide.]]></description>
										<content:encoded><![CDATA[<p>Patients are receiving individual notifications after a healthcare software vendor disclosed a breach that may affect roughly 3.8 million people nationwide, according to recent independent reporting.</p>
<p>Unlimited Technology Systems, a third-party provider of practice-management software and revenue-cycle services, says an unauthorized actor obtained copies of some individuals’ information between October 5 and October 10, 2025. The company discovered unauthorized activity in its commercial data center on October 19, 2025, according to state filings and the sample <a href="https://www.consumer.sc.gov/identity-theft-unit/security-breach-notices" rel="nofollow noopener" target="_blank">consumer</a> notice.</p>
<p>Unlimited began providing notices on approximately July 21, 2026, and is sending them on a rolling basis. That rollout is what makes the incident newly relevant for patients who may not have known that a vendor serving their medical provider was involved.</p>
<h2>Why one vendor’s breach can reach many patients</h2>
<p>Unlimited provides administrative, practice-management and financial technology services to healthcare organizations and providers. Its role as a third-party vendor means information from patients at unrelated medical practices may have been stored or processed through the same company.</p>
<p>Provider notices describe Unlimited as the vendor involved in the incident. One provider notice says the incident did not involve that provider’s own computer systems or disrupt patient care. That does not mean every patient at an affected practice was involved: notices are being sent to individuals identified through reviews by Unlimited and the relevant data owners.</p>
<h2>What information may be involved</h2>
<p>The categories varied by individual. Depending on the person, potentially involved information may include:</p>
<ul>
<li>Names, dates of birth and demographic information;</li>
<li>Social Security numbers, driver’s licenses or other government identification;</li>
<li>Email addresses, physical addresses and phone numbers;</li>
<li>Insurance cards, policy and claims information, intake forms and patient-balance information; and</li>
<li>Medical record numbers, dates of service and diagnosis information.</li>
</ul>
<p>The notices do not establish that every listed category was exposed for every person who receives a letter. Some provider notices also say Social Security numbers may have been involved for only some patients.</p>
<h2>What the notice says was not involved</h2>
<p>Unlimited’s sample notice says full patient medical records, medical imaging, credit-card information and bank-account information were not involved. The same notice separately lists medical record numbers, dates of service and diagnosis information as data that may have been involved, so patients should read their individualized letters rather than assume that all health-related information was excluded.</p>
<p>Unlimited says it was unaware of any attempted or actual misuse of the information when the notices were issued. The disclosure does not establish that notified individuals have experienced identity theft.</p>
<h2>How large is the incident?</h2>
<p><a href="https://www.techradar.com/pro/security/us-healthcare-software-giant-unlimited-technology-systems-admits-hackers-may-have-stolen-sensitive-data-of-3-8-million-people" rel="nofollow noopener" target="_blank">TechRadar</a> reported on August 10, 2026, that the broader incident may affect approximately 3.8 million people. That is an independent report of the national scope, not a final government-confirmed count presented in the state filings cited here.</p>
<p>Other reporting has described at least 442,000 affected patients based on notices and disclosures available at the time. State records show the incident reaches multiple states: an Iowa filing lists 162,478 Iowa residents, while a South Carolina state record lists 148,342 affected residents.</p>
<p>Those figures illustrate how a breach at a healthcare technology vendor can spread across multiple provider networks. They should not be added together as a national total because the available reports may cover overlapping or differently updated populations.</p>
<h2>What notified consumers should do</h2>
<p>Individuals who receive a letter should use the contact information in that notice and activate the offered services before the deadline printed in the letter. Unlimited says notified individuals are being offered 24 months of identity monitoring, fraud consultation and identity-theft restoration through Kroll. Monitoring can help identify suspicious activity, but it does not prevent fraud or guarantee reimbursement.</p>
<p>Consumers should review their credit reports, bank and payment-account statements, insurance explanations of benefits and medical-account activity for unfamiliar changes. A one-year fraud alert may be appropriate for some people. Those seeking stronger protection can consider a security freeze with each of the three major credit bureaus.</p>
<p>Anyone who sees suspected identity theft or unauthorized financial activity should contact the relevant financial institution and appropriate authorities promptly. People who believe they may be affected but did not receive a notice can call Unlimited’s incident-response line at <strong>844-576-3063</strong>.</p>
<h2>Sources</h2>
<ul>
<li><a href="https://www.iowaattorneygeneral.gov/media/cms/7212026_Unlimited_Technology_System_0B86CFE2EF213.pdf" rel="nofollow noopener" target="_blank">Iowa Attorney General breach notification filed by Unlimited Technology Systems</a></li>
<li><a href="https://oag.ca.gov/system/files/Unlimited%20-%20Exhibit%20A%20-%20Sample%20Individual%20Notice.pdf" rel="nofollow noopener" target="_blank">California Attorney General sample individual notice</a></li>
<li><a href="https://www.techradar.com/pro/security/us-healthcare-software-giant-unlimited-technology-systems-admits-hackers-may-have-stolen-sensitive-data-of-3-8-million-people" rel="nofollow noopener" target="_blank">TechRadar report on the approximately 3.8 million figure</a></li>
<li><a href="https://www.consumer.sc.gov/identity-theft-unit/security-breach-notices" rel="nofollow noopener" target="_blank">South Carolina Department of Consumer Affairs breach notice listing</a></li>
</ul>
]]></content:encoded>
					
					<wfw:commentRss>https://111things.com/national/healthcare-software-breach-may-expose-data-of-3-8-million-people/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">947165</post-id>	</item>
		<item>
		<title>IRS watchdog says digital-first service left some filers behind</title>
		<link>https://111things.com/national/irs-watchdog-says-digital-first-service-left-some-filers-behind/</link>
					<comments>https://111things.com/national/irs-watchdog-says-digital-first-service-left-some-filers-behind/#respond</comments>
		
		<dc:creator><![CDATA[Brian Bateman]]></dc:creator>
		<pubDate>Fri, 14 Aug 2026 16:57:52 +0000</pubDate>
				<category><![CDATA[National]]></category>
		<category><![CDATA[Consumer services]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[IRS]]></category>
		<category><![CDATA[Tax refunds]]></category>
		<category><![CDATA[Taxpayer Advocate]]></category>
		<category><![CDATA[United States]]></category>
		<guid isPermaLink="false">https://111things.com/?p=946984</guid>

					<description><![CDATA[The IRS processed most 2026 returns successfully, but its taxpayer watchdog found long delays and limited help for people needing manual review or identity assistance.]]></description>
										<content:encoded><![CDATA[<p>The <a href="https://www.irs.gov/newsroom/national-taxpayer-advocate-issues-2026-mid-year-report-to-congress" rel="nofollow noopener" target="_blank">IRS</a> processed most 2026 tax returns successfully, but taxpayers whose cases fell outside automated processing often faced long delays and limited access to human help, the National Taxpayer Advocate said in a report released June 24, 2026.</p>
<p>The advocate’s <em>Fiscal Year 2027 Objectives Report to Congress</em> describes a mixed filing season. The IRS processed nearly 139 million individual returns and issued more than 90 million current-year refunds. About 98% of individual returns were filed electronically. About 98% of refunds were delivered by direct deposit, although the report notes that the IRS’s direct-deposit and refund totals are not directly comparable because they include different tax-year populations.</p>
<p>Those topline figures do not capture the experience of millions of people whose returns were suspended, whose refunds could not be sent electronically or whose cases required identity-theft assistance.</p>
<h2>Where automated processing breaks down</h2>
<p>More than 14 million individual returns were suspended during processing for additional review. A suspension is not, by itself, a finding of fraud or identity theft. It can mean that an IRS filter flagged a return and the agency needs more information or verification before releasing a refund.</p>
<p>More than 1 million taxpayers did not receive refunds within the IRS’s normal processing time. Those taxpayers waited an average of about 5.5 weeks, according to the report. Other taxpayers experienced shorter delays that remained within the agency’s normal time frame.</p>
<p>The delays can be financially significant for households relying on a refund for rent, groceries, medical bills or other expenses. The report says taxpayers who need individualized help often struggle more than those whose returns can be completed through automated systems.</p>
<p>Phone access was also uneven. Across IRS telephone lines, assistors answered about 21% of 48.1 million calls during the filing season, compared with 25% of calls in the prior filing season. The report says some high-volume lines performed particularly poorly, including the Taxpayer Protection Program line used by people whose returns were suspended because of suspected identity theft.</p>
<h2>Why paper-refund recipients faced extra obstacles</h2>
<p>The IRS generally shifted toward electronic payments during the filing season. That approach does not work for everyone. People who are unbanked or underbanked, some older taxpayers, certain taxpayers living overseas and others without practical access to electronic payments may need a paper check.</p>
<p>By April 27, the IRS had issued about 4 million notices involving returns that lacked valid direct-deposit information or contained incorrect information. The notices generally directed taxpayers to use an online account to update payment information or request an exception for a paper check.</p>
<p>The National Taxpayer Advocate said the process was confusing because many taxpayers did not have online accounts or could not create them. The notices also did not clearly provide all the information needed to request an exception. The report says paper-refund problems caused delays of six weeks or more in some cases.</p>
<h2>Identity-theft cases can take nearly two years</h2>
<p>Identity-theft cases remained one of the most serious service problems. More than 500,000 cases were still pending at the end of the filing season, and the average resolution period was about 20 months.</p>
<p>That is an average, not a guaranteed wait for every taxpayer. But the backlog can leave affected households waiting for refunds long after ordinary processing timelines have passed.</p>
<p>Taxpayers who receive a CP5071-series notice or Letter 5447C should follow the instructions on the notice and use the official IRS verification service when available. The IRS says taxpayers should have the notice and the relevant Form 1040 return available. After verification, the agency says taxpayers should wait two to three weeks before checking refund status, and processing can take up to nine weeks.</p>
<h2>What taxpayers should do</h2>
<ul>
<li><strong>Read every IRS notice carefully.</strong> Use the notice number and tax year to identify the required response and deadline.</li>
<li><strong>Verify identity only through official IRS tools.</strong> Do not send Social Security numbers, tax returns or bank information through unofficial websites, messages or callers claiming to represent the IRS.</li>
<li><strong>Check an IRS Online Account and Where’s My Refund?</strong> These tools provide different information. An online account can show notices and account details, while the refund tracker provides status updates.</li>
<li><strong>Consider an Identity Protection PIN.</strong> An IP PIN can help prevent someone else from filing a federal return using a taxpayer’s Social Security number or ITIN.</li>
<li><strong>Seek additional help when ordinary channels fail.</strong> Taxpayer Assistance Centers offer in-person service by appointment. The <a href="https://www.taxpayeradvocate.irs.gov/reports/2027-objectives-report-to-congress/newsroom-27/" rel="nofollow noopener" target="_blank">Taxpayer Advocate Service</a> may help when a taxpayer faces financial hardship or cannot resolve a serious problem through normal IRS channels.</li>
</ul>
<h2>What happens next</h2>
<p>The report sets out the Taxpayer Advocate Service’s priorities for fiscal year 2027, including reducing identity-theft delays, improving communication when returns are suspended and making paper-refund procedures clearer.</p>
<p>Those priorities are recommendations and advocacy objectives, not completed IRS reforms. The report’s central distinction is that digital-first tools can serve many taxpayers well, but they cannot replace meaningful telephone, in-person, correspondence and case-resolution options for people with unusual circumstances or limited digital access.</p>
<p>For taxpayers, the practical lesson is simple: a strong filing-season topline does not mean every refund is moving normally. If the IRS freezes a return or requests identity verification, the notice and official IRS tools are the starting point; if those channels fail and the delay creates serious hardship, in-person assistance or the Taxpayer Advocate Service may be the next step.</p>
<h2>Sources</h2>
<ul>
<li><a href="https://www.irs.gov/newsroom/national-taxpayer-advocate-issues-2026-mid-year-report-to-congress" rel="nofollow noopener" target="_blank">IRS: National Taxpayer Advocate issues 2026 mid-year report to Congress</a></li>
<li><a href="https://www.taxpayeradvocate.irs.gov/reports/2027-objectives-report-to-congress/newsroom-27/" rel="nofollow noopener" target="_blank">Taxpayer Advocate Service: FY 2027 Objectives Report to Congress</a></li>
<li><a href="https://apnews.com/article/treasury-irs-tax-audits-dec4ec8f4f8817d5d7a8d55490338fb0" rel="nofollow noopener" target="_blank">Associated Press: IRS watchdog cites long phone waits during tax season</a></li>
</ul>
]]></content:encoded>
					
					<wfw:commentRss>https://111things.com/national/irs-watchdog-says-digital-first-service-left-some-filers-behind/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">946984</post-id>	</item>
		<item>
		<title>AssuranceAmerica says breach exposed data of nearly 7 million people</title>
		<link>https://111things.com/national/assuranceamerica-says-breach-exposed-data-of-nearly-7-million-people/</link>
					<comments>https://111things.com/national/assuranceamerica-says-breach-exposed-data-of-nearly-7-million-people/#respond</comments>
		
		<dc:creator><![CDATA[Brian Bateman]]></dc:creator>
		<pubDate>Wed, 05 Aug 2026 05:57:42 +0000</pubDate>
				<category><![CDATA[National]]></category>
		<category><![CDATA[Consumer Protection]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Insurance]]></category>
		<category><![CDATA[United States]]></category>
		<guid isPermaLink="false">https://111things.com/?p=941134</guid>

					<description><![CDATA[AssuranceAmerica says a March incident may have exposed insurance, driver and identity data for 6,998,886 people. Here’s what consumers should do.]]></description>
										<content:encoded><![CDATA[<p>AssuranceAmerica Managing General Agency LLC says personal information belonging to 6,998,886 people may have been exposed in a cyber incident involving insurance and driver-related records.</p>
<p>The company began sending formal notices on July 10, 2026, after completing its review of potentially affected files on June 15. An Indiana attorney general breach listing reports that 237,141 Indiana residents were affected; the filing lists the national total as 6,998,886. The Indiana figure is a state-specific count and does not mean all affected people lived in Indiana.</p>
<h2>What changed</h2>
<p>The incident itself occurred in March. AssuranceAmerica says it detected suspicious activity on March 17, while the Indiana filing lists March 16 as the breach date. The company says the activity appeared to target an employee and that an unauthorized third party accessed parts of its information-technology environment and copied data files.</p>
<p>AssuranceAmerica says it investigated the incident, worked to determine which files were involved and completed that review on June 15. The notification period began July 10, making the current issue for consumers the formal notice and response period rather than a newly discovered attack.</p>
<h2>What information may be involved</h2>
<p>The company’s notice says the potentially exposed information may include names, addresses and other contact details; insurance policy or account information; driver and vehicle information; claims data; and driver’s-license numbers.</p>
<p>For some individuals, the information may also include Social Security numbers or tax-identification information. The notice does not say that every affected person’s record contained every category.</p>
<p>The combination of insurance records, driver information and identity details can make phishing or impersonation attempts more convincing. A message that references a policy, vehicle, claim or license should not automatically be treated as legitimate simply because it includes personal information.</p>
<h2>What AssuranceAmerica says it did</h2>
<p>According to the company’s notice, affected systems were taken offline, passwords were reset and additional monitoring and threat-detection tools were put in place. AssuranceAmerica also says it expanded employee instruction and notified law enforcement.</p>
<p>The company is offering eligible recipients 12 months of IDX credit monitoring. Consumers should use the enrollment instructions in their individual notice and activate the service by the deadline printed in that letter. Credit monitoring can help identify certain signs of misuse, but it does not prevent identity theft by itself.</p>
<h2>What affected consumers should do</h2>
<p>First, verify that a notice is genuine. Do not rely on an unexpected email or text message asking for information. Use the contact details in the letter or another trusted company contact method, and avoid clicking links in unsolicited messages.</p>
<p>If you received a notice, enroll in the offered IDX service before its stated deadline. Review your credit reports, bank statements, insurance accounts and claims activity for unfamiliar changes.</p>
<p>Consumers whose Social Security or tax-identification information may have been included should consider placing a free credit freeze with Equifax, Experian and TransUnion. A fraud alert is another free option that asks lenders to take additional steps to verify identity before opening new credit.</p>
<p>Anyone who suspects identity theft should report it through IdentityTheft.gov and contact the affected financial institution, insurer or account provider promptly.</p>
<h2>What remains unknown</h2>
<p>AssuranceAmerica has not publicly identified the person or group behind the incident. The available notice also does not establish the precise method used to target the employee, whether the information was publicly released or whether it was sold. The company’s account confirms unauthorized access and copying of files, but not those additional details.</p>
<h2>Sources</h2>
<ul>
<li><a href="https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/DataBJune26.pdf" rel="nofollow noopener" target="_blank">Indiana Attorney General, June 2026 Data Breach Report</a></li>
<li><a href="https://www.classaction.org/media/assuranceamerica-data-breach-notice-2026.pdf" rel="nofollow noopener" target="_blank">AssuranceAmerica individual data-security incident notice</a></li>
<li><a href="https://techcrunch.com/2026/07/08/another-massive-data-breach-exposed-millions-of-drivers-license-numbers/" rel="nofollow noopener" target="_blank">TechCrunch report on the AssuranceAmerica breach</a></li>
<li><a href="https://consumer.ftc.gov/media/79862" rel="nofollow noopener" target="_blank">Federal Trade Commission, “What To Do After a Data Breach”</a></li>
</ul>
]]></content:encoded>
					
					<wfw:commentRss>https://111things.com/national/assuranceamerica-says-breach-exposed-data-of-nearly-7-million-people/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">941134</post-id>	</item>
		<item>
		<title>IRS warns tax preparers that cyberattacks can delay taxpayer refunds</title>
		<link>https://111things.com/national/irs-warns-tax-preparers-that-cyberattacks-can-delay-taxpayer-refunds/</link>
					<comments>https://111things.com/national/irs-warns-tax-preparers-that-cyberattacks-can-delay-taxpayer-refunds/#respond</comments>
		
		<dc:creator><![CDATA[Brian Bateman]]></dc:creator>
		<pubDate>Tue, 04 Aug 2026 20:08:05 +0000</pubDate>
				<category><![CDATA[National]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[IRS]]></category>
		<category><![CDATA[Tax Fraud]]></category>
		<category><![CDATA[Taxes]]></category>
		<category><![CDATA[United States]]></category>
		<guid isPermaLink="false">https://111things.com/?p=940574</guid>

					<description><![CDATA[An IRS summer campaign urges tax professionals to strengthen security as stolen credentials and client data can lead to fraudulent filings and refund delays.]]></description>
										<content:encoded><![CDATA[<p>The <a href="https://www.irs.gov/newsroom/written-information-security-plans-are-essential-for-tax-pros" rel="nofollow noopener" target="_blank">IRS</a> and its Security Summit partners are warning tax professionals that a compromised preparer account or computer system can expose taxpayer information, enable fraudulent filings and delay legitimate refunds.</p>
<p>The national warning is part of the five-week “Protect Your Clients; Protect Yourself” campaign launched July 7, 2026. The campaign is being reinforced through the IRS Nationwide Tax Forums, including the New Orleans forum taking place August 4-6.</p>
<h2>What the IRS is warning about</h2>
<p>The campaign identifies several schemes aimed at tax professionals. They include IRS impersonation by email, text, phone or direct message; misleading tax advice posted on social media; malicious messages from supposed new clients; and attempts to steal professional credentials and records, including an Electronic Filing Identification Number, or EFIN, a Preparer Tax Identification Number, or PTIN, and Centralized Authorization File, or CAF, information.</p>
<p>The IRS says criminals may pose as prospective clients and send links or attachments disguised as tax documents. Preparers are being urged to verify unusual requests through trusted channels instead of clicking unexpected links or opening files from unfamiliar contacts.</p>
<h2>Why taxpayers can be affected</h2>
<p>Taxpayers may not know when a preparer’s system has been compromised, but stolen Social Security numbers, income records or tax-account information can be used to submit fraudulent returns. A return can also be selected for identity verification, delaying a refund even when the taxpayer filed a legitimate claim.</p>
<p>The Taxpayer Advocate Service reported that, from January 1 through April 18, 2026, the IRS selected about 2.6 million returns for review through its Taxpayer Protection Program and released about 1.2 million of the associated refunds. The report said 887,000 refunds were released after taxpayers completed identity verification, while 269,000 were released using IRS records without taxpayer interaction.</p>
<p>Those selections do not mean every return was fraudulent. The Taxpayer Advocate Service has warned that IRS filters can also hold legitimate returns, creating delays while taxpayers verify their information.</p>
<p>The watchdog also reported that more than 500,000 identity-theft victim assistance cases remained open and that victims were waiting about 20 months on average for the IRS to resolve their cases or release refunds. That is an identity-theft case-resolution figure, not the normal timeline for an IRS refund.</p>
<h2>Safeguards the IRS is emphasizing</h2>
<p>The IRS is telling tax professionals to use multifactor authentication, train employees, verify unusual requests and keep security procedures current. It also says tax professionals must maintain a written information security plan under applicable law.</p>
<p>The plan should be tailored to the size, scope and complexity of the business and to the sensitivity of the customer information it handles. IRS guidance says the plan should address employee training, information systems, system failures, risk assessment, safeguards and oversight of service providers. It should also be reviewed and updated as the business changes.</p>
<p>If a tax professional suspects a data breach, the IRS says the incident should be reported quickly to the agency’s Stakeholder Liaison and to the appropriate state tax agency. Early reporting can give the IRS a chance to block fraudulent returns filed in clients’ names and help guide the preparer through the response process.</p>
<h2>Steps taxpayers can take</h2>
<p>People who use a paid preparer can ask how the firm protects client data, whether it uses multifactor authentication and whether it maintains a written information security plan. Taxpayers should be cautious about unsolicited messages requesting passwords, tax credentials, payment information or an Identity Protection PIN.</p>
<p>Taxpayers with a Social Security number or Individual Taxpayer Identification Number can request a free IRS Identity Protection PIN. The PIN is a unique six-digit number known to the taxpayer and the IRS and is issued for use on federal tax returns. It helps verify the taxpayer’s identity, but it is not a guarantee against every type of tax fraud and does not promise an immediate refund.</p>
<p>The IRS says taxpayers must verify their identity before receiving an IP PIN. People who cannot complete the process online or by phone may have other options, including submitting Form 15227 when eligible or making an appointment at a Taxpayer Assistance Center.</p>
<h2>What happens next</h2>
<p>The IRS forums and summer campaign provide guidance and prevention measures; they do not create new tax rules or enforcement powers. After the New Orleans session, the remaining 2026 Nationwide Tax Forums are scheduled for New York City on August 18-20, Orlando on September 1-3 and San Diego on September 15-17.</p>
<h2>Sources</h2>
<ul>
<li><a href="https://www.taxpayeradvocate.irs.gov/wp-content/uploads/2026/06/JRC27_FullReport.pdf" rel="nofollow noopener" target="_blank">Taxpayer Advocate Service filing-season report</a></li>
<li><a href="https://www.irs.gov/newsroom/written-information-security-plans-are-essential-for-tax-pros" rel="nofollow noopener" target="_blank">IRS written security plan guidance</a></li>
</ul>
]]></content:encoded>
					
					<wfw:commentRss>https://111things.com/national/irs-warns-tax-preparers-that-cyberattacks-can-delay-taxpayer-refunds/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">940574</post-id>	</item>
		<item>
		<title>Amazon Settlement Highlights Identity-Theft Records Rights</title>
		<link>https://111things.com/national/amazon-settlement-highlights-identity-theft-records-rights/</link>
					<comments>https://111things.com/national/amazon-settlement-highlights-identity-theft-records-rights/#respond</comments>
		
		<dc:creator><![CDATA[Brian Bateman]]></dc:creator>
		<pubDate>Tue, 04 Aug 2026 09:18:06 +0000</pubDate>
				<category><![CDATA[National]]></category>
		<category><![CDATA[Amazon]]></category>
		<category><![CDATA[Consumer Protection]]></category>
		<category><![CDATA[Federal Trade Commission]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[United States]]></category>
		<guid isPermaLink="false">https://111things.com/?p=939955</guid>

					<description><![CDATA[The FTC’s June 30 Amazon settlement highlights a federal right identity-theft victims can use to request transaction records from businesses within 30 days.]]></description>
										<content:encoded><![CDATA[<p>A June 30, 2026, settlement involving Amazon is drawing attention to a federal right many identity-theft victims do not know they have: the ability to request records connected to fraudulent accounts and transactions.</p>
<p>The Federal Trade Commission said Amazon agreed to pay a $2.25 million civil penalty to resolve allegations that it violated the Fair Credit Reporting Act by failing to provide certain records to identity-theft victims within the law’s 30-day timeframe. The United States filed the complaint in federal court on June 29, 2026.</p>
<p>The case remains listed as pending on the <a href="https://www.ftc.gov/business-guidance/resources/businesses-must-provide-victims-law-enforcement-transaction-records-relating-identity-theft" rel="nofollow noopener" target="_blank">FTC</a>’s case page. The parties filed a proposed stipulated order, and Amazon neither admits nor denies the complaint’s allegations under that proposed order. The $2.25 million is a civil penalty payable to the United States, not a consumer refund program.</p>
<h2>What Section 609(e) allows victims to request</h2>
<p>Section 609(e) of the Fair Credit Reporting Act generally requires a business that provided goods, services or credit, accepted payment or otherwise entered into a commercial transaction involving someone who allegedly used another person’s identity without authorization to provide relevant application and business transaction records.</p>
<p>The records may help a victim or an investigating officer understand how a fraudulent account was opened or used. They may include information that identifies the alleged identity thief, but the law does not guarantee that the documents will identify the person responsible or lead to recovery of lost money.</p>
<p>The right is also limited. It does not require a company to provide every kind of data, and the statute excludes Internet navigational data and similar information about a person’s visit to a website or online service.</p>
<p>A request generally must be made in writing and sent to the address the business designates. The records may be sent to the victim or, if the victim specifies or authorizes it, directly to a federal, state or local law-enforcement agency.</p>
<h2>What to include in a request</h2>
<p>Federal guidance and the proposed Amazon order say a business may require documentation showing both the requester’s identity and the identity-theft claim. That can include:</p>
<ul>
<li>A government-issued identification document;</li>
<li>A police report; and</li>
<li>A completed identity-theft affidavit.</li>
</ul>
<p>Consumers should identify the suspected fraudulent account or transaction as specifically as possible, keep copies of everything submitted and use a delivery method that documents when the business received the request. They should send the request to the company’s designated address or channel, rather than relying only on a general customer-service conversation.</p>
<h2>How the 30-day deadline works</h2>
<p>Section 609(e) says the business must provide covered records no later than 30 days after receiving a qualifying request. The proposed Amazon order states that the 30-day period applies after Amazon receives the request, any preferred contact information it requires in good faith and any verification documents it requires in good faith.</p>
<p>That makes the paper trail important. Consumers should record the date they sent the request, the date of delivery, the designated business address, the documents included and the names or reference numbers from follow-up contacts. If a company says the request is incomplete, ask in writing what specific information is missing.</p>
<h2>What the complaint alleges about Amazon</h2>
<p>The complaint alleges that Amazon sometimes gave victims or authorized law-enforcement representatives explanations that obstructed access to records. The allegations include references to security or privacy concerns, requests that victims guess the name of the person who opened the fraudulent account, claims that representatives could not access the records and demands for subpoenas from law enforcement.</p>
<p>The filing also alleges delays and refusals in circumstances where the statute generally does not make a subpoena a prerequisite for an authorized law-enforcement request. It alleges that Amazon failed in some cases to provide records or even issue a denial within 30 days.</p>
<p>Those descriptions remain allegations. The proposed stipulated order would permanently bar the challenged practices, require Amazon to maintain a process for receiving Section 609(e) requests and require a website notice explaining how victims can request records. It would also require Amazon to identify certain eligible victims who previously submitted written requests but did not receive responsive records, then notify them about the process for requesting records again. The order would take effect only if entered by the court.</p>
<h2>When a company may refuse</h2>
<p>Section 609(e) does not create an unlimited right to every record. A business may decline a request in specified circumstances, including when it determines in good faith that the law does not require disclosure, lacks a high degree of confidence in the requester’s identity, finds that the request contains a relevant misrepresentation or determines that the information is excluded Internet navigational data.</p>
<p>The statute also recognizes a defense when the requested records do not exist or are not reasonably available after a reasonably diligent search. A company’s general security or privacy concern, a demand that the victim guess the alleged thief’s name or a representative’s lack of personal access is not automatically one of the listed grounds for denial.</p>
<h2>What to do if a company refuses or does not respond</h2>
<p>Ask for the denial and the reason in writing. Preserve the request, delivery confirmation, attachments and all responses. If law enforcement is investigating, provide the agency with the records and correspondence and ask whether it should submit its own authorized request.</p>
<p>Victims should handle related credit-reporting steps separately. The Consumer Financial Protection Bureau advises consumers to report identity theft, consider a fraud alert or credit freeze and dispute fraudulent accounts with the nationwide consumer-reporting companies. A transaction-record request does not replace those actions.</p>
<p>If the business does not respond within the applicable 30-day period or appears to impose requirements the law does not support, consumers can consider filing a complaint with the FTC or CFPB and contacting the relevant law-enforcement agency. The federal right is limited, but a careful written request can give victims and investigators access to records that may otherwise be difficult to obtain.</p>
<h2>Sources</h2>
<ul>
<li><a href="https://www.ftc.gov/business-guidance/resources/businesses-must-provide-victims-law-enforcement-transaction-records-relating-identity-theft" rel="nofollow noopener" target="_blank">FTC guidance on identity-theft transaction records</a></li>
<li><a href="https://www.consumerfinance.gov/ask-cfpb/what-do-i-do-if-i-am-a-victim-of-identity-theft-en-31/" rel="nofollow noopener" target="_blank">CFPB identity-theft recovery guidance</a></li>
</ul>
]]></content:encoded>
					
					<wfw:commentRss>https://111things.com/national/amazon-settlement-highlights-identity-theft-records-rights/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">939955</post-id>	</item>
		<item>
		<title>South Carolina reports 1.13 million affected residents in first-half breach notices</title>
		<link>https://111things.com/state-news/south-carolina-reports-1-13-million-affected-residents-in-first-half-breach-notices/</link>
					<comments>https://111things.com/state-news/south-carolina-reports-1-13-million-affected-residents-in-first-half-breach-notices/#respond</comments>
		
		<dc:creator><![CDATA[Brian Bateman]]></dc:creator>
		<pubDate>Mon, 03 Aug 2026 00:57:23 +0000</pubDate>
				<category><![CDATA[State News]]></category>
		<category><![CDATA[Consumer affairs]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Data Security]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[public safety]]></category>
		<category><![CDATA[South Carolina]]></category>
		<guid isPermaLink="false">https://111things.com/?p=936570</guid>

					<description><![CDATA[South Carolina consumer officials say 41 businesses reported breaches affecting 1,131,320 residents from January 1 through June 30, 2026. The figure is not a count of unique people, and two large notices drove about two-thirds of the reported total.]]></description>
										<content:encoded><![CDATA[<p>South Carolina businesses reported security breaches affecting 1,131,320 South Carolina residents during the first half of 2026, according to a July 6 report from the <a href="https://consumer.sc.gov/news/2026-07/more-11-million-south-carolinians-affected-security-breaches-so-far-2026" rel="nofollow noopener" target="_blank">South Carolina Department of Consumer Affairs</a>.</p>
<p>The figure covers breach notices received from January 1 through June 30. It is a total of reported affected residents, not a count of 1,131,320 uniquely identified people. The department&#8217;s broader reporting guidance says totals can be minimum figures when organizations cannot determine everyone affected.</p>
<h2>Financial businesses reported the largest share</h2>
<p>Forty-one businesses reported breaches during the six-month period. Financial businesses filed 12 notices involving 801,652 South Carolina residents.</p>
<p>Hospitality businesses reported four breaches affecting 154,455 residents. Education businesses reported three breaches affecting 91,842 residents.</p>
<p>A small number of large notices drove much of the statewide total. AssuranceAmerica Managing General Agency reported 611,046 affected South Carolina residents on June 18. Carnival Corporation reported 134,156 on May 28.</p>
<p>Those two notices together account for 745,202 reported residents, or about 66% of the first-half total. That calculation does not mean every person experienced the same exposure. The data involved can differ from one notice to another, so residents should read the notice from the organization involved.</p>
<h2>Later registry entries are outside the first-half total</h2>
<p>The South Carolina Department of Consumer Affairs&#8217; public registry was updated through July 23, 2026. It includes notices reported after June 30, including MCBS, LLC, which listed 295,625 affected South Carolina residents on July 1, and Unlimited Technology Systems, LLC, which listed 148,342 on July 21.</p>
<p>Those entries should not be added to the 1,131,320 first-half total. The July 6 report measured notices received during the January-through-June period, while the registry continues to change as businesses submit additional notices.</p>
<h2>What the state registry shows</h2>
<p>South Carolina businesses must notify residents when their personal information is breached. When a business sends notice to 1,000 or more South Carolina residents at one time, it must also notify the Department of Consumer Affairs and provide a copy of the consumer notice. Notices received by the department are posted publicly.</p>
<p>The registry can show the organization, reporting date and reported number of affected South Carolina residents. It is not a complete count of every breach or every affected person. The department says the affected-resident field may be blank when a business does not know the number. Businesses reporting a breach affecting fewer than 1,000 South Carolina residents may also choose whether to provide the department with a copy of the notice.</p>
<p>The department&#8217;s 2026 historical report says some organizations were unable to determine a precise number of affected consumers even after investigating. In those cases, the reported totals represent minimum numbers, not an independently audited count of every person whose information may have been exposed.</p>
<h2>Steps to take after receiving a notice</h2>
<p>Residents who receive a breach notice should act promptly rather than wait for evidence of fraud.</p>
<ul>
<li>Change the password for the affected account and any other account where the same password was used.</li>
<li>Turn on multifactor authentication and use unique passwords for important accounts.</li>
<li>Review bank, credit-card and other financial statements for unauthorized activity.</li>
<li>Obtain free credit reports through AnnualCreditReport.com.</li>
<li>Consider placing a fraud alert with a credit-reporting agency. An alert requires businesses to take additional steps to verify identity before issuing credit or services in your name.</li>
<li>Consider placing a security freeze with each of the three major credit-reporting agencies. A freeze can help prevent new accounts from being opened in your name until you lift it.</li>
</ul>
<p>If a notice says a driver&#8217;s license, identification card or passport may have been exposed, contact the agency that issued the document. The South Carolina Department of Consumer Affairs Identity Theft Unit also offers guidance at 800-922-1594.</p>
<p>The statewide total shows the volume of reported exposure, but it does not establish that every listed resident suffered identity theft or financial loss. The individual notice remains the best source for what information was involved, what protections are offered and what deadlines apply.</p>
<h2>Sources</h2>
<ul>
<li><a href="https://consumer.sc.gov/news/2026-07/more-11-million-south-carolinians-affected-security-breaches-so-far-2026" rel="nofollow noopener" target="_blank">South Carolina Department of Consumer Affairs: First-half 2026 breach report</a></li>
<li><a href="https://spectrumlocalnews.com/sc/south-carolina/news/2026/03/18/south-carolina-breach-report-consumer" rel="nofollow noopener" target="_blank">Spectrum News: SCDCA reports decline in security breaches</a></li>
</ul>
]]></content:encoded>
					
					<wfw:commentRss>https://111things.com/state-news/south-carolina-reports-1-13-million-affected-residents-in-first-half-breach-notices/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">936570</post-id>	</item>
		<item>
		<title>FTC requires Amazon to pay $2.25M over identity-theft victims’ FCRA records requests</title>
		<link>https://111things.com/law/ftc-requires-amazon-to-pay-2-25m-over-identity-theft-victims-fcra-records-requests/</link>
					<comments>https://111things.com/law/ftc-requires-amazon-to-pay-2-25m-over-identity-theft-victims-fcra-records-requests/#respond</comments>
		
		<dc:creator><![CDATA[Brian Bateman]]></dc:creator>
		<pubDate>Mon, 13 Jul 2026 21:01:08 +0000</pubDate>
				<category><![CDATA[Law]]></category>
		<category><![CDATA[Local Headlines]]></category>
		<category><![CDATA[Consumer Protection]]></category>
		<category><![CDATA[FCRA]]></category>
		<category><![CDATA[Federal Trade Commission]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Technology Privacy]]></category>
		<category><![CDATA[United States]]></category>
		<guid isPermaLink="false">https://111things.com/?p=926263</guid>

					<description><![CDATA[FTC says Amazon violated FCRA Section 609(e) by refusing or delaying identity-theft record requests. Proposed settlement: $2.25M + victim notice.]]></description>
										<content:encoded><![CDATA[<p>The Federal Trade Commission says Amazon mishandled <strong>identity-theft victims’ requests for certain application and business transaction records</strong> under <strong>Section 609(e) of the Fair Credit Reporting Act (FCRA)</strong>. On <strong>June 30, 2026</strong>, the <a href="https://www.ftc.gov/news-events/news/press-releases/2026/06/ftc-requires-amazon-pay-225-million-resolve-charges-it-knowingly-violated-fair-credit-reporting-act" rel="nofollow noopener" target="_blank">FTC</a> announced a proposed resolution that would require Amazon to pay <strong>$2.25 million</strong>.</p>
<p>The related court papers were filed <strong>June 29, 2026</strong>. The FTC also asked the court to enter a <strong>stipulated order</strong> that, if approved, would include <strong>notice and outreach</strong> so eligible victims learn how to request the records and so some people who previously requested records can be reached with instructions.</p>
<h2>What the FTC alleges Amazon did wrong under FCRA Section 609(e)</h2>
<p>In its complaint, the FTC alleges Amazon <strong>refused to provide</strong> some covered records and, in other instances, <strong>failed to respond within the FCRA’s required 30-day timeframe</strong>. The FTC also alleges Amazon sometimes pointed to <strong>security or privacy</strong> reasons to deny requests—claims the FTC argues are not permitted under the Section 609(e) framework.</p>
<h2>The key compliance deadline: 30 days</h2>
<p>A major issue in the case is timing. The FTC’s complaint alleges Amazon did not provide application and business transaction records <strong>not later than 30 days</strong> after eligible identity-theft victims requested them.</p>
<h2>What the proposed stipulated order would require (beyond payment)</h2>
<p>According to the FTC’s proposed order documents, Amazon would have to:</p>
<ul>
<li><strong>Provide website notice</strong> describing how identity-theft victims can request covered records</li>
<li><strong>Send records within 30 days</strong> after receiving qualifying requests (subject to the Section 609(e) process and verification requirements described in the court papers)</li>
<li><strong>Do outreach</strong> aimed at reaching eligible victims and certain people who previously requested records but did not receive them</li>
</ul>
<p>As always in FTC enforcement announcements, readers should treat this as <strong>resolution of allegations</strong> through a proposed stipulated order—until the court enters an order on the terms described in the case packet.</p>
<h2>Who’s affected—and what to watch next</h2>
<p>The practical impact is on <strong>identity-theft victims</strong> trying to obtain <strong>application and business transaction records</strong> tied to fraudulent activity. The FTC’s focus is not just on broad privacy policy—it’s on whether companies follow <strong>the legally required records-request timing rules</strong>.</p>
<p>What to watch next:</p>
<ul>
<li><strong>Whether and when the court enters the stipulated order</strong> on the FTC’s proposed terms</li>
<li><strong>Whether the FTC uses this case as a template</strong> for similar enforcement around Section 609(e) response-handling</li>
</ul>
<p>If you are an identity-theft victim pursuing records under Section 609(e), a practical takeaway is to <strong>keep documentation of your request and dates</strong>—because this case underscores that federal regulators treat the <strong>30-day</strong> response requirement as a core compliance obligation.</p>
<h2>Sources</h2>
<ul>
<li><a href="https://www.ftc.gov/news-events/news/press-releases/2026/06/ftc-requires-amazon-pay-225-million-resolve-charges-it-knowingly-violated-fair-credit-reporting-act" rel="nofollow noopener" target="_blank">FTC press release (June 30, 2026): Amazon to pay $2.25 million over alleged FCRA Section 609(e) violation</a></li>
</ul>
]]></content:encoded>
					
					<wfw:commentRss>https://111things.com/law/ftc-requires-amazon-to-pay-2-25m-over-identity-theft-victims-fcra-records-requests/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">926263</post-id>	</item>
	</channel>
</rss>
