ID theft protection service LifeLock misled consumers again and violated 2010 settlement, FTC says in a lawsuit demanding company to repay customers
Shares of cybersecurity company LifeLock … Reuters : LifeLock crashes after regulators accuse it of violating deal Priya Anand / MarketWatch : Lifelock failed to protect customer data, FTC charges Charisse Jones / USA Today : FTC demands LifeLock redress consumers after violating court order Katie Lobosco / CNNMoney : FTC: LifeLock protection service doesn't live up to its name Marley Jay / Associated Press : Feds say ID protector LifeLock violated $12M settlement Cory Bennett / The Hill : Feds go after LifeLock, alleging poor data security Wall Street Journal : LifeLock Accused of Violating U.S. Settlement Over Deception Dino Grandoni / New York Times : F.T.C. Accuses LifeLock of Violating Settlement Ashlee Kieler / Consumerist : Complaint Alleges LifeLock Violated 2010 FTC Settlement By Continuing To Make False Claims Jeff John Roberts / Fortune : FTC says LifeLock lied and failed to protect consumers - again Seeking Alpha : FTC accuses LifeLock of violating settlement; shares -25% (updated)
Context & Ripple Effects
LifeLock signed a 2010 settlement with the FTC — reportedly worth $12M — that required it to protect customer data, and the agency now says the company broke both that deal and its marketing claims, filing a lawsuit that seeks direct repayment to subscribers. The suit lands mid-arc of an aggressive FTC run on data-handling firms: weeks earlier the FTC charged broker LeapLab with selling consumers' financial details to fraudsters, and the Wyndham data-breach case was still open.
The complaint is also a credibility attack on the product itself: an identity-theft protection service accused of not protecting identities is the worst possible headline for a subscription business built entirely on trust.
First-order effects
- LifeLock faces a court fight over customer redress on top of its existing obligations, and the market repriced immediately — Reuters reported the stock crashed on the accusation.
- Current subscribers gain a potential repayment claim, while prospective ones get an FTC-documented reason to question whether the service delivers what its name promises.
Second-order effects
- Rival ID-theft monitoring services can differentiate on verified compliance, forcing the category toward audited security practices rather than marketing assurances.
- Every other company living under an FTC consent decree sees that violations convert a settled penalty into renewed litigation — the same escalation logic visible in the FTC's separate pursuit of Wyndham over three data breaches.
Third-order effects
- If the pattern holds, FTC settlements function less as final resolutions than as ongoing contracts whose breach compounds costs — a structure the FTC applied again years later when 23andMe paid $30M after a breach exposed 6.9M customers' data.
- Consumer-facing data-security claims drift from advertising puffery toward regulated assertions, pushing identity-protection and data brokers like LeapLab's peers into a de facto compliance regime enforced through repeated lawsuits rather than new legislation.
The trend: The FTC is converting consumer data-security promises into enforceable obligations where a breached settlement triggers escalating penalties, making privacy compliance a recurring cost of doing business rather than a one-time fine.