LIFELOCK

Organization dossier FTC matters 2010 & 2015 Status: acquired, still operating

To prove identity theft was solved, the CEO printed his real Social Security number on billboards and TV. Then his identity got used to take out a loan — the first of thirteen reported incidents. The FTC billed the company $12 million, then came back and billed it $100 million more. The number on the billboard was real. So were the penalties.

My name is Todd Davis. My Social Security number is 457-55-5462.

LifeLock's national advertising, 2007 — CEO Todd Davis publishing his own SSN on billboards, on the side of a truck, and in television spots, per the FTC's filed advertisement exhibits and HuffPost

… the same high-level safeguards used by financial institutions … [alerts sent] “as soon as” [it received any indication a consumer may be a victim].

LifeLock's own marketing claims, as quoted in the FTC's 2015 filing describing what the company advertised, per the FTC

ENTITY
LifeLock, Inc., Tempe, Arizona — identity-theft-protection service; co-founded 2005 by Richard Todd Davis and Robert J. Maynard FACT
PRINCIPAL
Todd Davis, co-founder & CEO — the advertised face of the company; the SSN stunt is his, the penalties are the company's FACT
THE STUNT
2007 — the CEO broadcasts his real SSN nationwide to prove confidence in the product. It becomes the most-quoted marketing decision in the industry, for reasons the company did not intend
THE PENALTIES
$12M FTC + 35-state settlement (2010, vote 4–0) · $100M FTC order-enforcement settlement (2015, vote 3–1) — the FTC's largest order-enforcement award at the time FACT
RECORD
No fraud adjudication after trial appears in this record. Both matters were resolved by settlement / stipulated order; the company did not admit the FTC's allegations. The "deceptive" and "false" characterizations are the FTC's. FACT
STATUS
ACQUIRED, STILL OPERATING — bought by Symantec for $2.3 billion (2017); now a Norton / NortonLifeLock brand, still sold

This one is a company, not a person — but it chose to speak through a single man's Social Security number, so the CEO appears throughout. Keep the two distinct; this file does. What follows is the whole spectacle in order: the stunt, the thefts, the first FTC order, the record penalty, the acquisition.

The premise sold here was reassurance: pay us, and your identity is safe. The premise was tested in the most literal way available — on the CEO himself, in public, by anyone who saw the billboard. That is why the archive exists. Every beat below carries its receipt. Both sides get the microphone. You decide who wins.

the drama timeline

ACT I — THE BILLBOARD (2007)

Every confidence display begins with a wager the displayer believes he cannot lose. This one is printed at highway scale and read aloud on television. Watch what the public does with a number it was handed for free.

  1. 2007

    The CEO publishes his own SSN

    To advertise that its service makes identity theft a solved problem, LifeLock runs a national campaign built around CEO Todd Davis's actual Social Security number — 457-55-5462 — on billboards, on the side of a delivery truck, and in television spots. The FTC's own account later notes the number was even broadcast "from a bullhorn." The pitch: this is how confident we are.

ACT II — THE PREDICTABLE PART (2007–2008)

A number handed to everyone is used by someone. The only question was how fast, and by how many.

  1. 2007

    The $500 loan in Texas

    Within months, a man in Texas uses Davis's published number to take out a $500 loan in his name. The point the billboard was making about the product is now being made about the product, by strangers, at Davis's expense.

  2. 2007–2008

    Thirteen reported incidents

    Over 2007 and 2008, Davis reports thirteen separate instances in which his identity is misused — per contemporaneous reporting, mostly small-dollar or attempted. The billboard number becomes the industry's favorite cautionary tale about the gap between an advertising promise and what a monitoring service can actually stop.

    Note the mechanism the product could not touch: a fraud alert flags a new account being opened. It does not un-hand a number the CEO handed out on a billboard.

ACT III — THE FIRST ORDER (2010)

The regulator arrives with thirty-five states behind it and a narrower reading of what the advertising actually promised versus what the service actually did.

  1. MAR 2010

    $12 million, and 35 states

    The FTC and the attorneys general of 35 states settle with LifeLock and Davis for $12 million — then one of the largest FTC-state coordinated settlements. The FTC alleged the company's identity-theft-protection claims were deceptive: fraud alerts, the FTC noted, are most effective against new-account fraud, which its 2007 survey put at roughly 17 percent of identity-theft incidents — leaving existing-account misuse uncovered. The FTC further alleged LifeLock's claims about its own data security "were not true." The Commission vote was 4–0.

ACT IV — THE RECORD PENALTY (2015)

A consent order is a promise with a court behind it. The FTC returns to argue the promise was broken, and asks for a number nobody in its order-enforcement history had been asked for before.

  1. DEC 2015

    $100 million — the largest of its kind

    The FTC charges that LifeLock violated the 2010 order and settles the contempt case for $100 million — which the FTC calls, in its own words, "the largest monetary award obtained by the Commission in an order enforcement action." The FTC alleged four breaches: that from Oct 2012–Mar 2014 LifeLock failed to maintain a comprehensive information-security program; that it falsely advertised the "same high-level safeguards used by financial institutions"; that it falsely advertised it would send alerts "as soon as" it saw a sign of theft; and that it failed the order's recordkeeping requirements. Of the $100M, $68 million was earmarked for consumer redress via a parallel class action; the rest to state AGs and the FTC.

    The molt of the modern era: a promise about "bank-grade" safeguards, priced at the exact moment the safeguards were alleged to be absent.

  2. DEC 2015

    One commissioner votes no

    The order was not unanimous. The Commission approved it 3–1, with Commissioner Maureen Ohlhausen voting no and issuing a dissenting statement. Whatever the majority found, one of the FTC's own members did not agree the record carried it. That dissent is part of the public record and stays on this page.

  3. 2017

    The acquisition

    Symantec buys LifeLock for $2.3 billion. The brand survives the penalties, the mockery, and the CEO's number; it is folded into what becomes NortonLifeLock and is still sold today. Colonies of this species do not die when a display fails. They get acquired.

both sides, on the record

The stunt backfired on its own terms: the CEO published his SSN to prove the product worked, and the published number was then used to take out a $500 loan — the first of thirteen reported misuse incidents [5] [7]. The demonstration the ad intended and the demonstration it produced were opposites.

The regulator came twice. In 2010 the FTC and 35 states alleged the identity-theft-protection and data-security claims were deceptive and settled for $12 million [2]. In 2015 the FTC alleged the company had violated that very order — failing to maintain the required security program, falsely advertising "bank-grade" safeguards and instant alerts — and settled for $100 million, "the largest monetary award obtained by the Commission in an order enforcement action" [1].

The through-line: the FTC's charge in both matters is that the marketing promised more protection than the service delivered — a gap the CEO's own billboard had already illustrated, for free, years earlier [3].

Settlements, not verdicts. Both FTC matters were resolved by settlement / stipulated order, not by a court finding of fraud after trial, and LifeLock did not admit the FTC's allegations. "Deceptive" and "false" are the FTC's characterizations; a stipulated order, as the FTC's own note says, "has the force of law when approved" — it is not an adjudication that the company defrauded anyone [1] [2].

A sitting commissioner dissented. The $100 million order passed 3–1; Commissioner Maureen Ohlhausen voted no and filed a dissent. The FTC itself was not unanimous that the record supported the action [1].

The underlying service is real. Identity monitoring and fraud alerts are a legitimate product, and — as the FTC itself noted — fraud alerts are genuinely effective against new-account fraud, the category they target. The SSN campaign was marketing; the reported thefts were, per the coverage, largely minor or attempted, and Davis remained solvent and in his job [2] [7]. The company remediated, extended its recordkeeping obligations, continued operating, and was acquired by Symantec for $2.3 billion — the market's verdict on the brand's survival [7] [9].

YOU DECIDE

Scoped to the claims, never the company — and never the man. The claim "publishing my SSN proves your identity is safe with us" lost its own argument in public: the number was used within months, thirteen reported times, and the stunt is now taught as the opposite of what it meant to prove. The claim "the advertising matched the service" is the FTC's to press, and the FTC pressed it twice, for $12 million and then $100 million — but by settlement, without an admission, and over one commissioner's dissent. Nothing here is a post-trial fraud finding. The penalties are facts; the word "deceptive" wears the FTC's badge, not ours.

Weigh the costly signals: the company paid $112 million in total to the government and consumers, and paid its CEO's own credit history to make an ad. The one experiment that would settle the premise — hand your Social Security number to the entire country and stay untouched — was run, on camera, by the CEO. It returned thirteen results, and none of them was "untouched."

The archive does not judge. The archive merely keeps the tape running.

evidence locker

PRIMARY RECORD

  1. FTC — "LifeLock to Pay $100 Million to Consumers to Settle FTC Charges it Violated 2010 Order" (Dec 2015) FACT — the $100M settlement, the four alleged order violations, the "largest monetary award… in an order enforcement action" language, and the 3–1 vote with Ohlhausen's dissent. ftc.gov/news-events/…/lifelock-pay-100-million-…
  2. FTC — "LifeLock Will Pay $12 Million to Settle Charges by the FTC and 35 States…" (Mar 2010) FACT — the first settlement, the deceptive-claims allegations, the 17%-of-incidents fraud-alert context, the 4–0 vote. ftc.gov/news-events/…/lifelock-will-pay-12-million-…
  3. FTC — LifeLock advertisement exhibits (filed, 2010) PRIMARY — the actual ads, including the CEO's published SSN, as filed in the FTC's case. ftc.gov/sites/default/files/documents/cases/2010/03/100309lifelockexhibits.pdf

PRESS & COMMENTARY

  1. Computerworld — "LifeLock pays $100M to settle FTC complaint of more false advertising" ATTRIBUTED — press account of the 2015 order and the market-value drop. computerworld.com/article/3017178/…
  2. Phoenix New Times — "LifeLock Ordered to Pay $100 Million for Deceptive Ads and Bad Security" ATTRIBUTED — local reporting on the settlement. phoenixnewtimes.com/news/…-7903740
  3. Inside Privacy (Covington) — "FTC Obtains Record $100 Million Settlement with LifeLock" ATTRIBUTED — legal-industry summary of the order. (Host returns 403 to automated fetches; the page is live in a browser.) insideprivacy.com/data-security/ftc-obtains-record-100-million-settlement-with-lifelock/
  4. Yahoo Finance — "The founder of the identity theft prevention company Symantec bought reportedly had his identity stolen 13 times" ATTRIBUTED — the SSN stunt, the $500 loan, the thirteen incidents. finance.yahoo.com/news/symantec-just-bought-identity-theft-215041068.html
  5. HuffPost — "Remembering Todd Davis: Laughing Stock of LifeLock" ATTRIBUTED — the campaign and its aftermath, in commentary register. huffpost.com/entry/remembering-todd-davis-laughing-stock-of-lifelock…
  6. Wikipedia — "LifeLock" REFERENCE — the 2007 campaign, the FTC actions, and the $2.3B Symantec acquisition (Feb 2017), with onward citations. en.wikipedia.org/wiki/LifeLock
The standard. Everything above is sourced to the FTC's own press releases and filed exhibits, to the parties' settlements, and to named press reporting. The penalties are stated as facts; the FTC's "deceptive" and "false" characterizations are stated as the FTC's findings and allegations, never adopted as our own. The company is distinguished from its CEO, a settlement is distinguished from an adjudication of fraud, and the defense — the non-admission, the dissenting commissioner, the legitimacy of the underlying service, and the company's survival and acquisition — is presented at full strength. No motive is asserted, no private character diagnosed. The burden of proof is on us, not the subject. If it couldn't survive a defamation challenge, it wouldn't be on this page.