"Yeah," Zorn said. "Your name's on here." Then he told me the exact date that Coast Capital had accessed our credit reports. It was unnerving.
The 20-year-old Zorn bought the computer at a Goodwill location in Scott for $9 and found the sensitive personal financial information for 764 of Coast Capital's customers. When he alerted the company of the problem and tried to sell it back to Coast Capital, the mortgage company claimed that Zorn was trying to extort $3,500 for the return of the information.
As I read the local media accounts, I kept wondering how my information ' that I supplied to Coast Capital years ago ' ended up for sale in a Goodwill store? Why wasn't it disposed of? And if Zorn hadn't gone public with the story, how would I have ever known that my personal financial history had been donated to Goodwill? As a consumer, I thought these were reasonable questions. But instead, the media focus seemed to be on Zorn, "the extortionist."
Cathy Leblanc, Coast Capital's Louisiana operations division manager, informed me that the company was sending out letters that would fill me in on the details. When I explained that I had questions as a reporter as well, I was told that I would need to talk to Coast Capital CEO Robert Genisman, who was out of the office that day.
In the meantime, I paid Robert Zorn a visit.
In his apartment living room in Lafayette, Zorn looked quite at home in front of his computer, flanked by three monitors and two keyboards. He was surrounded by computer parts ' motherboards, printers and monitors. In the corner of the room, a full-sized, disemboweled video arcade game flashed images across its monitor.
Zorn was dressed in shorts, T-shirt and sandals and was thumbing through a restraining order delivered to him that day. He voluntarily handed the computer over to the district attorney's office the day before, but kept a list of the names that were found on the computer.
"[Coast Capital] is not going to tell these people," Zorn says. "They have a right to know what happened to their information. [Coast Capital] says that I listed the names online. I never once listed the names online. I put an email address, and if they emailed with a first name, middle initial and last name, I replied to them 'yes' or 'no.' These people have a right to know."
Coast Capital's attorney, Michael Hebert, argues in the restraining order that Zorn's possession of any of Coast Capital's customers' information is a "potential violation of the law, including, but not limited to, the privacy provisions of the Graham [sic] Leach Bliley Act." The Gramm-Leach-Bliley Act includes provisions to protect consumers' personal financial information held by financial institutions, such as mortgage companies like Coast Capital. The GLB Act's Safeguard Rule requires financial institutions to design, maintain and implement a security plan that protects the confidentiality and integrity of consumers' information.
"Their lawyer said that I have no right releasing the names," Zorn says. "They had no right in releasing it to me in the first place. Why did this information get out? They're not sure how. Nobody says anything about that."
Zorn says he kept none of the financial data and that he hasn't had the time to respond to 200 emails in his email account from people asking if their information was on the computer. Through his Web site, www.zorntech.net, Zorn has been telling his story of how he acquired the computer.
On the evening of April 12, after buying the computer that day, he tested it and found it had a bad power supply. He replaced the power supply and, voila, the machine came alive. After it booted up, the computer began searching for a network connection. Zorn cancelled the action and went to the computer's desktop. In a folder he accessed a file titled "usernames and passwords" where he found access to all of Coast Capital's programs.
"They took no precautions in securing this information," he says. "Everything was on the desktop." He says he accessed about five documents before he realized what he was looking at ' loan applications, bank account numbers, credit reports, names, addresses and Social Security numbers. Nearly 800 Coast Capital customers had their information on this one machine.
The next day, Wednesday, April 13, Zorn called an acquaintance he thought worked for Coast Capital. The acquaintance no longer worked there but gave Zorn the cell phone number of the Coast Capital employee whose name was on the computer. (Zorn declined to identify the employee.) He contacted the worker that afternoon, who told him that she had donated the computer to Goodwill. Zorn asked what Coast Capital's procedure was for handling this situation, and according to him, the employee replied, "I'm sure you can just go ahead and delete it." Zorn said he needed for her to talk to the company about exactly how to proceed.
Zorn says he spoke again with a Coast Capital representative on Thursday, April 14, and with Genisman on Friday and that his cell phone records confirm his claims.
Coast Capital contends ' both in its restraining order and in an interview ' that the first contact the company had with Zorn was on April 15, the day that it also contacted Lafayette police. Zorn's cell phone records indicate that two days had passed before Coast Capital notified police. "We took aggressive and immediate action to regain this information and secure it," Genisman wrote in a letter to select Coast Capital customers.
In an interview with Genisman, the CEO says he spoke to Zorn once on the afternoon of April 15.
"I immediately called him and said, 'How do we work together? What can we do here?' And he said, 'Give me $3,500 by 6 o'clock this evening, or' ' I don't really remember what he said the 'or' was. He just demanded the $3,500. And I said, 'This sounds like extortion to me.' He said, 'That's what it's worth. I didn't pay very much for it, but it's worth that to me. And that's how much I would get for it on the open market.' And that sounded very suspicious."
Zorn doesn't deny asking for $3,500. "I'm not an idiot," he says. "I've made sure that this is not extortion. One newspaper said I demanded money by 6 that afternoon. What I said was, 'I want to hear back from you before 6 o'clock.' This was when I was fed up. I didn't say I had to have the money by 6 o'clock.
"The information was never for sale because I never owned the information," Zorn continues. "The value to me was my loss of time. That's how I make my living ' buying junk, fixing it and selling it. They want to say it was a $9 computer. I bought a $20 accordion that sold for $600 online. I bought a 1952 Sears Silvertone reel-to-reel recorder that sold for $400 online. It's the buy low, sell high market. I always said this computer was for sale. I never said, 'Buy this computer, or I'm going to the DA.'"
Zorn says he went to the district attorney's office, on Monday, April 18, explained his situation and asked what to do with the computer's hard drive. He claims he was contacted by the DA's office a week later, only after local media picked up on the story. (Calls placed to the DA's office were not returned by press time.)
"The only basis [Coast Capital] has for extortion charges is the value I was asking over what I paid for it," says Zorn. "That's ridiculous. The Goodwill value is not a retail value."
Cpl. Mark Francis of the Lafayette Police Department says an investigation is ongoing, but no charges have been filed against Zorn.
Rather than contact all its customers ' and because Coast Capital still doesn't know how many customers' records were on the computer ' it sent letters to approximately 80 concerned customers who had contacted the company about the incident. Genisman wrote: "The man contacted Coast Capital and instead of willingly turning over the information for a reasonable price, he demanded $3,500 for the return of the computer and the information."
I asked Genisman what would have been a reasonable price. "I told him if it's worth $300 or $400, fine. Further, I would be willing to buy it back for that amount, plus $100 or $150 for your trouble, or I will put a new hard drive in for you. And he wasn't having any of that." Zorn claimed the offer was for $100, and he declined.
I also wanted to know where the computer was used before it surfaced in the Goodwill store. Initial media accounts stated that a Coast Capital employee had used the computer in a home. In his letter, Genisman described it as "a computer owned personally by an employee of Coast Capital."
Why would sensitive customer information be stored on someone's personal computer within a home? What measures had been taken to make sure that the employee's family members or friends didn't access that information? If the computer was connected to the Internet, was there a firewall in place or any other security measures to protect the information from outside access?
Genisman says, "Well, it wasn't a personal computer. It was personally owned by one of our employees who used it for the purpose of operating as a loan agent in the office, and that was it. When it left the office, we believed ' but that's part of our investigation ' that the information was erased."
He adds that Coast Capital has no idea how the computer found its way to the Goodwill store. "That's one of the problems we have here that we're working on," he said. "We have an internal investigation going on, obviously, to determine which computer it was, what was on there, where it came from, how it got to where it was going and therefore, I don't think I can answer the question or should answer the question now, until we are sure of the correct answer."
In his letter to the 80 customers, Genisman wrote: "Coast Capital is confident and has been informed that to date no confidential customer information has been distributed ... This is the first incident of loss of confidential information ever experienced."
"Robert Genisman said that he's confident, that he knows this has never happened," Zorn says. "I could have never said anything, and he would have never known this happened."
The Federal Trade Commission's focus is to protect consumers. One of its jobs is to enforce federal consumer protection laws, like the Gramm-Leach-Bliley Act, which protects consumers' financial information held by financial institutions. To learn more about this act, visit www.ftc.gov/privacy/glbact/
For more information on privacy issues, your rights as a consumer, or to register a complaint with the Federal Trade Commission, visit www.ftc.gov/privacy/
Links of Interest
Here's your daily look at late-breaking national and international news, upcoming events and the stories that will be talked about Monday, December 09, 2013:
If all 44 projects are approved, about $300 million would remain in the fund set up as a down payment to help the Gulf.
Last week, the Saints gave up 429 yards to Seattle, second most in a game this season.
Since Anthony Jennings and Brooks Haack were not expected to contribute until next year at the earliest, it seemed like a sneak peek at hidden Christmas gifts.
Louisiana National Guard personnel seeking benefits for same-sex spouses will have an easier time filing the requests, despite a state refusal to let its workers process the paperwork.
Panthers coach Ron Rivera sees one potential flaw with his team's stellar defensive play so far this season. "Apparently we like to bite on the double moves," Rivera said.
Computer hackers may have gained access to the personal information of thousands of Louisiana residents who use debit cards issued by JPMorgan Chase for three state agencies, authorities said Wednesday.
Jim Purcell, who has been in the job since February 2011, notified the Board of Regents about his decision at its monthly meeting.
Hushed plans for a commercial development along the Louisiana Avenue portion of the Holy Rosary campus put the future of longtime tenant EarthShare Gardens in jeopardy.
If a recent advertisement in The Daily Advertiser is any indication, speculation the local daily will be implementing the “Butterfly Project” could be more of a reality than the Gannett-owned paper’s top execs are willing to admit.
Mettenberger injured his left knee while unloading a 32-yard completion in the fourth quarter of No. 14 LSU's 31-27 victory over Arkansas last Friday, and LSU coach Les Miles confirmed the severity of the injury on Wednesday.
An ordinance to phase out a 2 percent rebate to Lafayette merchants for collecting and remitting on time sales taxes cleared the City-Parish Council by a 6-3 vote.
Louisianans are the fourth most likely to use profanity yet also the fourth most likely to be courteous. So, please, just kiss my a** ... if it’s not too much trouble.
The state Coastal Protection and Restoration Authority voted Tuesday to authorize two lawsuits against the U.S. Army Corps of Engineers.
A long night on the field in Seattle got even worse off of it, and now the Saints are operating on a compressed time-frame as they brace for surging Carolina with first place in the NFC South at stake.
Public school letter grades, teacher evaluations and student promotion won't be affected by Louisiana's shift to more rigorous educational standards for two years, the state's top school board decided Tuesday.
Vitter told The Associated Press that he is sending an email to supporters Wednesday and is in discussions with his family about the possibility.
The Ragin' Cajuns go for New Orleans Bowl three-peat, this time against the Tulane Green Wave, which is making its first postseason appearance since the Hawaii Bowl in 2002.
Louisiana has joined four other states in filing a so-called “friend of the court” brief in support of Mississippi’s lawsuit against the federal government over new flood insurance rates set to go into effect.
Kerry Wayne Bertrand was charged Monday for the alleged killing of his stepdaughter, Skylar Lee Credeur, a UL Lafayette chemistry major found dead in the bathtub of her family home in August.
Louisiana's state school board is considering a two-year delay for some consequences tied to the phase-in of more rigorous educational standards, called Common Core, at public schools.
The most anticipated game in the NFC this season was a laugher.
The attorneys for Busted in Acadiana administrator Chris Hebert got an extra 2.5 months Monday to prepare for their client’s felony trial, marking the third time the case has been delayed this year.
In an effort to ease tensions, Lafayette Parish Superintendent of Schools Dr. Pat Cooper is calling for board approval of two day-long workshops: one to address lingering questions caused by Act 1 of the 2012 Legislature, and a session focused on mending the tattered relationship between the board and administration.
Lafayette has so much going for it, and so much yet to do.