Quantcast

Sears Sued Over Privacy Breach

Robert McMillan, IDG News Service

  • 0 Yes
  • 0 No

Sears Holdings is facing a class-action lawsuit after making the purchase history of its customers public on its Managemyhome.com Web site.

The lawsuit seeks damages as well as an accounting by Sears to determine whether the Web site was misused by criminals. It was filed on Friday by New Jersey resident Christine Desantis, who is represented by KamberEdelson, a technology law firm. KamberEdelson is best known for its recent settlement with social networking site Facebook over its sending of unwanted text messages to recycled cell-phone numbers.

"It's a pretty simple case," said Jay Edelson, a partner with the Chicago-based law firm. "Sears decided to put private information of its customers up on the Web site and make it publicly available. They did it without telling their customers that it was going to happen ... and they really did it for their own financial reasons."

Manage My Home is a community portal where Sears shoppers can download product manuals, find product tips and get home renovation ideas. The Web site had a feature called "Find your products" that ostensibly was designed to help users look up past purchases.

Last Thursday, researchers at security vendor CA pointed out that the feature could be used to look up the purchase history of any Sears customer, an apparent violation of the company's privacy policy.

Manage My Home could easily have been misused by criminals, Edelson said. For example, a robber could gain access to a victim's home by posing as a Sears repair person, using the information available on the site. That could be incredibly scary, he said. "They have a duty to keep that information away from the public."

Sears disabled the "Find your products" feature on Friday, saying it would re-introduce the feature once the company figures out a way of ensuring that the information cannot be viewed by unauthorized third parties.

However, the retailer was informed of the problem weeks before it took the feature off-line, Edelson said.

In late December, CA researchers also criticized Sears for downloading invasive comScore Web tracking software onto the desktops of some members of its MySHCcommunity.com Web site without adequate disclosure.

KamberEdelson is also investigating that matter, Edelson said.

  • Recommend this story?
  • 0 Yes
    0 No

"Sears Sued Over Privacy Breach" Comments

Related Security Articles

  • CDW Virtualization Center What is Virtualization and how can it help you save money? Click here to find out.
  • Cisco Small Business Center Does your network give your business an advantage. Click here to find out...
  • HP Ink Center Bring improved color and brilliance to your printed material. Visit the Resource Center for more info...

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)