"Yeah," Zorn said. "Your name's on here." Then he told me the exact date that Coast Capital had accessed our credit reports. It was unnerving.
The 20-year-old Zorn bought the computer at a Goodwill location in Scott for $9 and found the sensitive personal financial information for 764 of Coast Capital's customers. When he alerted the company of the problem and tried to sell it back to Coast Capital, the mortgage company claimed that Zorn was trying to extort $3,500 for the return of the information.
As I read the local media accounts, I kept wondering how my information ' that I supplied to Coast Capital years ago ' ended up for sale in a Goodwill store? Why wasn't it disposed of? And if Zorn hadn't gone public with the story, how would I have ever known that my personal financial history had been donated to Goodwill? As a consumer, I thought these were reasonable questions. But instead, the media focus seemed to be on Zorn, "the extortionist."
Cathy Leblanc, Coast Capital's Louisiana operations division manager, informed me that the company was sending out letters that would fill me in on the details. When I explained that I had questions as a reporter as well, I was told that I would need to talk to Coast Capital CEO Robert Genisman, who was out of the office that day.
In the meantime, I paid Robert Zorn a visit.
In his apartment living room in Lafayette, Zorn looked quite at home in front of his computer, flanked by three monitors and two keyboards. He was surrounded by computer parts ' motherboards, printers and monitors. In the corner of the room, a full-sized, disemboweled video arcade game flashed images across its monitor.
Zorn was dressed in shorts, T-shirt and sandals and was thumbing through a restraining order delivered to him that day. He voluntarily handed the computer over to the district attorney's office the day before, but kept a list of the names that were found on the computer.
"[Coast Capital] is not going to tell these people," Zorn says. "They have a right to know what happened to their information. [Coast Capital] says that I listed the names online. I never once listed the names online. I put an email address, and if they emailed with a first name, middle initial and last name, I replied to them 'yes' or 'no.' These people have a right to know."
Coast Capital's attorney, Michael Hebert, argues in the restraining order that Zorn's possession of any of Coast Capital's customers' information is a "potential violation of the law, including, but not limited to, the privacy provisions of the Graham [sic] Leach Bliley Act." The Gramm-Leach-Bliley Act includes provisions to protect consumers' personal financial information held by financial institutions, such as mortgage companies like Coast Capital. The GLB Act's Safeguard Rule requires financial institutions to design, maintain and implement a security plan that protects the confidentiality and integrity of consumers' information.
"Their lawyer said that I have no right releasing the names," Zorn says. "They had no right in releasing it to me in the first place. Why did this information get out? They're not sure how. Nobody says anything about that."
Zorn says he kept none of the financial data and that he hasn't had the time to respond to 200 emails in his email account from people asking if their information was on the computer. Through his Web site, www.zorntech.net, Zorn has been telling his story of how he acquired the computer.
On the evening of April 12, after buying the computer that day, he tested it and found it had a bad power supply. He replaced the power supply and, voila, the machine came alive. After it booted up, the computer began searching for a network connection. Zorn cancelled the action and went to the computer's desktop. In a folder he accessed a file titled "usernames and passwords" where he found access to all of Coast Capital's programs.
"They took no precautions in securing this information," he says. "Everything was on the desktop." He says he accessed about five documents before he realized what he was looking at ' loan applications, bank account numbers, credit reports, names, addresses and Social Security numbers. Nearly 800 Coast Capital customers had their information on this one machine.
The next day, Wednesday, April 13, Zorn called an acquaintance he thought worked for Coast Capital. The acquaintance no longer worked there but gave Zorn the cell phone number of the Coast Capital employee whose name was on the computer. (Zorn declined to identify the employee.) He contacted the worker that afternoon, who told him that she had donated the computer to Goodwill. Zorn asked what Coast Capital's procedure was for handling this situation, and according to him, the employee replied, "I'm sure you can just go ahead and delete it." Zorn said he needed for her to talk to the company about exactly how to proceed.
Zorn says he spoke again with a Coast Capital representative on Thursday, April 14, and with Genisman on Friday and that his cell phone records confirm his claims.
Coast Capital contends ' both in its restraining order and in an interview ' that the first contact the company had with Zorn was on April 15, the day that it also contacted Lafayette police. Zorn's cell phone records indicate that two days had passed before Coast Capital notified police. "We took aggressive and immediate action to regain this information and secure it," Genisman wrote in a letter to select Coast Capital customers.
In an interview with Genisman, the CEO says he spoke to Zorn once on the afternoon of April 15.
"I immediately called him and said, 'How do we work together? What can we do here?' And he said, 'Give me $3,500 by 6 o'clock this evening, or' ' I don't really remember what he said the 'or' was. He just demanded the $3,500. And I said, 'This sounds like extortion to me.' He said, 'That's what it's worth. I didn't pay very much for it, but it's worth that to me. And that's how much I would get for it on the open market.' And that sounded very suspicious."
Zorn doesn't deny asking for $3,500. "I'm not an idiot," he says. "I've made sure that this is not extortion. One newspaper said I demanded money by 6 that afternoon. What I said was, 'I want to hear back from you before 6 o'clock.' This was when I was fed up. I didn't say I had to have the money by 6 o'clock.
"The information was never for sale because I never owned the information," Zorn continues. "The value to me was my loss of time. That's how I make my living ' buying junk, fixing it and selling it. They want to say it was a $9 computer. I bought a $20 accordion that sold for $600 online. I bought a 1952 Sears Silvertone reel-to-reel recorder that sold for $400 online. It's the buy low, sell high market. I always said this computer was for sale. I never said, 'Buy this computer, or I'm going to the DA.'"
Zorn says he went to the district attorney's office, on Monday, April 18, explained his situation and asked what to do with the computer's hard drive. He claims he was contacted by the DA's office a week later, only after local media picked up on the story. (Calls placed to the DA's office were not returned by press time.)
"The only basis [Coast Capital] has for extortion charges is the value I was asking over what I paid for it," says Zorn. "That's ridiculous. The Goodwill value is not a retail value."
Cpl. Mark Francis of the Lafayette Police Department says an investigation is ongoing, but no charges have been filed against Zorn.
Rather than contact all its customers ' and because Coast Capital still doesn't know how many customers' records were on the computer ' it sent letters to approximately 80 concerned customers who had contacted the company about the incident. Genisman wrote: "The man contacted Coast Capital and instead of willingly turning over the information for a reasonable price, he demanded $3,500 for the return of the computer and the information."
I asked Genisman what would have been a reasonable price. "I told him if it's worth $300 or $400, fine. Further, I would be willing to buy it back for that amount, plus $100 or $150 for your trouble, or I will put a new hard drive in for you. And he wasn't having any of that." Zorn claimed the offer was for $100, and he declined.
I also wanted to know where the computer was used before it surfaced in the Goodwill store. Initial media accounts stated that a Coast Capital employee had used the computer in a home. In his letter, Genisman described it as "a computer owned personally by an employee of Coast Capital."
Why would sensitive customer information be stored on someone's personal computer within a home? What measures had been taken to make sure that the employee's family members or friends didn't access that information? If the computer was connected to the Internet, was there a firewall in place or any other security measures to protect the information from outside access?
Genisman says, "Well, it wasn't a personal computer. It was personally owned by one of our employees who used it for the purpose of operating as a loan agent in the office, and that was it. When it left the office, we believed ' but that's part of our investigation ' that the information was erased."
He adds that Coast Capital has no idea how the computer found its way to the Goodwill store. "That's one of the problems we have here that we're working on," he said. "We have an internal investigation going on, obviously, to determine which computer it was, what was on there, where it came from, how it got to where it was going and therefore, I don't think I can answer the question or should answer the question now, until we are sure of the correct answer."
In his letter to the 80 customers, Genisman wrote: "Coast Capital is confident and has been informed that to date no confidential customer information has been distributed ... This is the first incident of loss of confidential information ever experienced."
"Robert Genisman said that he's confident, that he knows this has never happened," Zorn says. "I could have never said anything, and he would have never known this happened."
The Federal Trade Commission's focus is to protect consumers. One of its jobs is to enforce federal consumer protection laws, like the Gramm-Leach-Bliley Act, which protects consumers' financial information held by financial institutions. To learn more about this act, visit www.ftc.gov/privacy/glbact/
For more information on privacy issues, your rights as a consumer, or to register a complaint with the Federal Trade Commission, visit www.ftc.gov/privacy/
Links of Interest
Cuban baseball isn't working; Syrians flee to Turkey; Maven arrives at Mars and more national and international news for Monday, September 22, 2014.
Monday's Blogs from the Bog!
Despite sweeping changes enacted by Gov. Bobby Jindal's administration, the health insurance program for state workers and public school employees will have to use $88 million from its reserve fund to cover its costs this year.
The LPSB races are sure to get heated between now and Nov. 4, and with only 9 available seats, this year's field of 20 candidates will surely be wanting to set themselves apart from the crowd early; they'll get their chance next week, starting Tuesday with the kick-off of a three-day series of candidate forums.
Lawmakers say they've received complaints that waits have spiked, with people being forced to wait in line for more than an hour — and sometimes three hours — to handle routine tasks.
The campaign announced that Rep. Stuart Bishop of District 43 and Nancy Landry, District 31, have thrown their support behind the Naval Academy graduate and entrepreneur in his bid to unseat current Hunter Beasley in District 8.
A Lafayette man with an alleged taste for child porn was busted Thursday evening during a cyber crime sting launched by the Attorney General’s Office.
U.S. Rep. Vance McAllister says his chief of staff is on temporary leave after being booked with drunken driving.
It was a rare moment in Congress this week as Republicans briefly put aside partisanship in support of President Barack Obama's request to train and arm Syrian rebels, and while a number of Democrats opposed the measure, Louisiana's Democratic Sen. Mary Landrieu found herself on the same side of the issue as her Republican challenger Rep. Bill Cassidy.
City-Parish President Joey Durel is asking the council to sign off on a resolution approving a pair of deals that would lead to razing the seedy Lesspay Motel at Four Corners to build a new police substation as well as transforming nearly a block Downtown where the old federal courthouse building now molders into a mixed-use development.
In 2013, the IRS — already the least popular governmental agency in the country — became the target of intense investigations after it was revealed that they had specifically and improperly scrutinized applications for tax-exempt status from organizations associated with the nascent Tea Party movement.
Improving the running game was "a point of emphasis" during the offseason and the results have manifested themselves in the form of substantially greater production.
Louisiana's health department said Wednesday that its evaluation of the state's Medicaid privatization was on target, despite criticism from the legislative auditor that it lacked key data and contained inconsistencies.
The feds converge on your office, seizing records on several employees as part of a pay-for-plea investigation. WWYD? If you’re Mike Harson, you give yourself a $12k raise.
It’s football season and after back-to-back winless weekends for the Saints and the Cajuns many citizens are finding it difficult to be civil much less happy. Well, chew on this.
Considering his repeated stays in the local penal system, David Narcisse Jr. should have known that having a semiautomatic shotgun, even one given to him by a friend, wasn’t the brightest of ideas.
A state district judge on Tuesday threw out a last-minute retirement hike lawmakers gave to the state police superintendent, ending a political firestorm over a pension boost passed without public scrutiny on the last day of the legislative session.
The House has passed a bill to increase oversight of veterans' hospitals under construction, following a report that some medical centers take three years longer to complete than estimated and cost an extra $366 million per project.
An obvious follow-up question for any Republican politician who accuses Democrats of being science deniers is one about science, to which Jindal bobbed and weaved like a welterweight champ.
The Lafayette City-Parish Council is expected to decide tonight (Tuesday) whether to go along with a proposal City-Parish President Joey Durel made in February’s State of the Parish Address and consolidate taxes for mosquito control and the parish health units into a broader tax program that would also cover animal control.
U.S. District Judge Richard Haik has dismissed Greg Davis’ lawsuit against the LPSB, yet in his ruling, the federal judge doesn’t bite his tongue in pointing out the "threat" being posed by certain board members.
Of all the political offices being contested throughout Lafayette Parish, the race for Broussard’s top police post has literally become one of the most heated.
A state district judge is deciding whether to issue an injunction against the enforcement of a last-minute retirement hike that lawmakers gave to the state police superintendent.
A new website is up for Louisiana's state government employees and retirees to choose their health insurance plans for next year, a choice they must make by October.
That fact that New Orleans led both games in the final 10 seconds of regulation, and lost each by a field goal or less, is of little solace.