Guess Settles FTC Complaint

Agency claims clothing retailer exposed consumers' credit card numbers to hackers after touting security of online information.

Clothing retailer Guess, Inc., has agreed to settle Federal Trade Commission (FTC) charges that it exposed consumers’ personal information, including credit card numbers, to computer hackers, contrary to the company’s claims. Guess’ online statements reassured consumers that their personal information would be secure and protected.

The Guess settlement prohibits the company from misrepresenting the extent to which it maintains and protects the security of personal information collected from or about consumers. It also requires that Guess establish and maintain a comprehensive information security program.

In addition, Guess must have its security program certified as meeting or exceeding the standards in the consent order by an independent professional within a year, and every other year thereafter.

The Guess consent decree is for settlement purposes only and does not constitution an admission of guilt. When the FTC issues a consent order on a final basis, the carries the force of law and any future violation of the order may result in a civil penalty up to $11,000.

“Consumers have every right to expect that a business that says it’s keeping personal information secure is doing exactly that,” said Howard Beales, director of the FTC’s Bureau of Consumer Protection. “It’s not just good business, it’s the law.”

Guess has sold Guess-brand clothing and accessories online at guess.com since 1998. According to the FTC complaint, since at least October 2000, Guess’ Web site has been vulnerable to commonly known attacks such as Structured Query Language (SQL) injection attacks and other Web-based application attacks.

Guess’ online statements told consumers that their personal information would be secure and protected. The company’s claims included, “This site has security measures in place to protect the loss, misuse, and alteration of information under our control.” The company also claimed, “All of your personal information, including your credit card information and sign-in password, are stored in an unreadable, encrypted format at all times.”

In fact, according to the FTC, the personal information was not stored in an unreadable, encrypted format at all times and Guess’ security measures failed to protect against SQL and other commonly known attacks. The FTC said that in February 2002, a visitor to the Web site, using an SQL injection attack, was able to read in clear text credit card numbers stored in Guess’ databases.

Subscribe to get your daily business insights

Whitepapers

US Mobile Streaming Behavior
Whitepaper | Mobile

US Mobile Streaming Behavior

5y

US Mobile Streaming Behavior

Streaming has become a staple of US media-viewing habits. Streaming video, however, still comes with a variety of pesky frustrations that viewers are ...

View resource
Winning the Data Game: Digital Analytics Tactics for Media Groups
Whitepaper | Analyzing Customer Data

Winning the Data Game: Digital Analytics Tactics for Media Groups

5y

Winning the Data Game: Digital Analytics Tactics f...

Data is the lifeblood of so many companies today. You need more of it, all of which at higher quality, and all the meanwhile being compliant with data...

View resource
Learning to win the talent war: how digital marketing can develop its people
Whitepaper | Digital Marketing

Learning to win the talent war: how digital marketing can develop its peopl...

2y

Learning to win the talent war: how digital market...

This report documents the findings of a Fireside chat held by ClickZ in the first quarter of 2022. It provides expert insight on how companies can ret...

View resource
Engagement To Empowerment - Winning in Today's Experience Economy
Report | Digital Transformation

Engagement To Empowerment - Winning in Today's Experience Economy

2m

Engagement To Empowerment - Winning in Today's Exp...

Customers decide fast, influenced by only 2.5 touchpoints – globally! Make sure your brand shines in those critical moments. Read More...

View resource