A U.S. Army soldier from 3/1 AD Task Force Bulldog uses his night vision equipment before an early morning joint patrol with Afghan National Army (ANA) soldiers in a village in Kherwar district in Logar province, eastern Afghanistan, May 22, 2012. REUTERS/Danish Siddiqui

Reuters Photojournalism

Our day's top images, in-depth photo essays and offbeat slices of life. See the best of Reuters photography.  See more | Photo caption 

Photo

Maxim Hot 100

The world's most beautiful women as chosen by Maxim readers.  Slideshow 

A cross is seen in Joplin, Missouri May 17, 2012. May 22 marks the one year anniversary of a deadly EF-5 tornado that ripped through the town, killing 161 people. The tornado damaged or destroyed about 7,500 homes and 500 other buildings, but the city is now well into a recovery mode that has spurred some segments of the local economy. REUTERS/Eric Thayer (UNITED STATES - Tags: DISASTER ENVIRONMENT RELIGION)

Joplin, one year after

May 22 marks the one year anniversary of a deadly tornado that ripped through Joplin, Missouri, killing 161 people.  Slideshow 

Exclusive: Citi skimps on "standard" customer monitoring

Related Topics

A man uses a Citibank automated teller machine at a branch in Washington January 19, 2010. REUTERS/Jim Young

A man uses a Citibank automated teller machine at a branch in Washington January 19, 2010.

Credit: Reuters/Jim Young

NEW YORK/BOSTON | Fri Jun 24, 2011 8:06am EDT

NEW YORK/BOSTON (Reuters) - After a massive data breach last month, Citigroup did not offer its hacked clients the same degree of identity-theft protection that many other companies provide, drawing criticism from privacy advocates.

Citigroup, which had over 360,000 credit card accounts exposed last month, sent letters to affected customers this month with advice on protecting themselves against identity theft.

But unlike other large U.S. companies breached by cybercriminals, Citigroup did not offer to buy or give all affected customers a year of preventive credit file monitoring services, according to a sample of a letter the bank sent to many customers and filed with regulators in Maine.

A year of monitoring has become a standard offering from large companies after customer information is hacked, to reassure clients and to protect them from identity theft, privacy and consumer advocates said.

"Consumers might want to turn to Citibank and ask them to do more. It's become pretty commonplace to offer credit monitoring these days," Ruth Susswein, the deputy director of national priorities for Consumer Action, told Reuters.

"That's really the standard thing they can do," she said.

The bank did remind consumers they could place a fraud alert on their credit files, which tells lenders to contact consumers before allowing an account to be opened in their name.

Credit monitoring services typically do more, such as tracking consumers' credit reports for signs that their identities have been stolen, and giving them early warnings of the theft.

Citigroup's letter to clients offers special services to customers who believe their identities have been stolen. Bank spokesman Sean Kevelighan said that clients calling a hotline mentioned in the letter would automatically be offered services including at least six months of monitoring.

Hackers failed to steal social security numbers with the Citi data breach. Generally, when social security numbers have not been compromised, there is little risk of new account fraud, said Paul Stephens, director of policy and advocacy for the Privacy Rights Clearinghouse, a San Diego nonprofit that tracks breaches.

But the services are relatively cheap and the offers now seem to be the norm after most breaches, he added.

The bank, already facing regulatory pressure over its delayed disclosure of the breach, now faces additional criticism from the advocates who call its response stingy.

"Citigroup needs to take this recent breach more seriously than they have," said Marc Rotenberg, executive director of the Electronic Privacy Information Center.

Rotenberg, who testified this week before the U.S. Senate's banking committee on cybersecurity in the financial sector, told Reuters that companies generally could take additional steps like reducing the amount of personal data they keep on file.

OPEN RECORDS

Citigroup, the third-largest U.S. bank, included a sample of the letter it sent to holders of 703 accounts in Maine, in a filing with the office of state Attorney General William Schneider. Maine is one of a number of states that require organizations to report when personal data is compromised. Officials provided the letter to Reuters in response to an open records request.

In its letter Citigroup advises customers to "remain vigilant during the next 12 to 24 months by monitoring your account activity," and tells them that they can place "fraud alerts" on their credit files.

Kevelighan did not directly say why the bank has not made a broader offer of free credit monitoring to date.

He said the bank is "tracking a nearly 90 percent satisfaction rate with customers contacting us who have been specifically impacted by this," based on assessments by the customer service agents who handle their calls. He also reiterated that customers would not be liable for any unauthorized use of their Citi accounts.

Citigroup has said that its cyberattackers did not steal its customers' social security numbers or card security numbers and "none of the data breached was sufficient to perpetrate fraud."

Privacy and security experts said hackers could still find ways to use customer names, account numbers and email addresses to steal their identities.

"We still think the breach is quite serious," Rotenberg said.

Monitoring hasn't always been common. TJX Companies initially declined to offer the service after it disclosed a major data breach in 2007, but it eventually offered three years of monitoring for some customers as part of a settlement of a class-action lawsuit.

Now the offers are more standard. Other documents from Maine outline a host of other data breaches at dozens of companies, universities and other organizations. In several cases, companies mentioned they would offer free credit-monitoring as part of their response, such as when the RiverSource funds unit of Ameriprise Financial said a former employee failed to return electronic devices containing client names and Social Security numbers.

(Editing by Steve Orlofsky)

Related Quotes and News

Company
Price
Related News
We welcome comments that advance the story through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can flag it to our editors by using the report abuse links. Views expressed in the comments do not represent those of Reuters. For more information on our comment policy, see http://blogs.reuters.com/fulldisclosure/2010/09/27/toward-a-more-thoughtful-conversation-on-stories/
Comments (3)
IntoTheTardis wrote:
Good to know. They’re off my list of potential banks and credit card companies.

Jun 24, 2011 11:24am EDT  --  Report as abuse
bugmenot0 wrote:
This is especially disturbing, since Citi is the exclusive credit card of the US government. Every government worker that has to go on travel is required to put all expenses on their Citi credit card. This card is not registered with the government, but with each individual worker. It is like their own personal credit card, but they cannot use it other than on travel. Many who work in the government would prefer not to have these cards, but they are forced on them. It’s kind of like a payoff to the great institution that is Citi.

Jun 24, 2011 12:02pm EDT  --  Report as abuse
UnionTom wrote:
I did not apply for a Citibank credit card, but I received 2 credit rejection letters (6/12/2011) from Citigroup, the letters were to my address but the name on the letter was a woman from Michigan. I called Citigroup and the person answering just told me to contact the credit bureau for help. He did not mention their recent data breach. I contacted Allclear ID & Debix (a service I was given after the Sony breach) and they failed to mention the databreach also. I had to learn from Lindedin.
I formerly held a credit card from Citibank so would assume my data was in their system and was compromised.

TR McDaniel
union11027@gmail.com

Jun 26, 2011 7:59am EDT  --  Report as abuse
This discussion is now closed. We welcome comments on our articles for a limited period after their publication.