Is Deceptively Getting People To Spam Their Friends Identity Theft?
from the seems-a-bit-strong dept
Last month, the social networking site Tagged got in some PR trouble after its attempt at "viral marketing" went a little haywire, causing lots of people to inadvertently spam their friends with invites to the service (and then those who signed up may have done the same). Such things are pretty common. They're deceptive and annoying, and companies that engage in them don't tend to last very long because no one really wants to use their service. But is it identity theft?
That seems to be the claim from NY Attorney General Andrew Cuomo who is suing the company, claiming that it "stole the address books and identities of millions of people." While we in no way endorse what Tagged did -- it is deceptive and scammy -- it's definitely seems like going over the line to call it identity theft, or even address book theft. Tagged apparently quickly pulled the plug on the campaign, and while there could be an action against the company for deceptive marketing practices, one would think that the company's reputation has been so damaged already that it's not going to be able to sign up many legitimate users. Tacking on attacks about privacy invasion and identity theft seems like bit much.

Reader Comments
(Flattened / Threaded)
Still though, compared to Cuomo's rants against Usenet and the like, this is almost sane.
(reply to this comment) (link to this comment)
Shouldn't we be abusing someone for not calling it "identity infringement?"
(reply to this comment) (link to this comment)
Facebook him Dano!
Hm either he wants to start the charges big and reduce them to charges more reasonable later, or he's a politician looking for headlines.
No, neither one of them make sense, he must think they are pirates and is trying to lull them into a false sense of security.
(reply to this comment) (link to this comment)
It's not identify theft
just social engineering. While I am sure it was really annoying and obnoxious it wasn't identify theft.
(reply to this comment) (link to this comment)
Is it trademark violation ? /s
(reply to this comment) (link to this comment)
People like that are the worst kind of idiot. People who sign up for stuff like that are the third worst kind of idiot (behind adults who still jam things up their noses).
(reply to this comment) (link to this comment)
How do we charge Andrew Cuomo with "issue theft?" He's created so many feel-good non-issues, usually resulting in needless restrictions our net freedoms rather than fighting any crime.
(reply to this comment) (link to this comment)
Maybe it is
I could actually see how one could consider it "identity theft". If Tagged takes my address, which it sounds like they did from the article, and spams my friends using *my* email as the original sender, then yeah, I can see it. They've hijacked my address book and sent emails that are "from" me, recommending they join. You've hijacked my email service and represented yourself as me, that's identity theft. You didn't really cost me anything monetarily, but you *did* steal my identity, however briefly.
(reply to this comment) (link to this comment)
I was on the receiving end of a wave of these. This was closer to phishing than to merely "deceptive practice".
*Many* companies are loosey goosey about the way that they use your address book data (when given permission) and "encourage" you to "spam" your friends. Facebook at times, Zynga at times, etc. That would be deceptive and annoying. This is far beyond. The way Tagged did it, privacy invasion and identity theft actually characterizes the act well.
Without permission, they misrepresent to get credentials, use those credentials to access your address book, spam friends pretending to be you, claiming to be sharing photos which are non-existent in order to induce your friends to click to repeat the process which results in (by their metric) a material gain for the company.
If Techdirt asked me for a username and password for one reason and then gave it a whirl to see if they could access my gmail account and download my address book with it, I would call that privacy invasion. Foolish me for using the same credentials, but that doesn't give the company a reason to rifle through accounts on multiple other services. Using that information sending out unsolicited emails pretending to be me inducing others to do the same and furthermore, doing it en masse, charging them with identity fraud sounds right too.
I'm more amazed the Attorney General was on the ball enough to notice this was different enough to file suit. Normally, I'd expect even this sort of egregiousness to fly completely under the radar.
(reply to this comment) (link to this comment)
Linkedin
They're deceptive and annoying, and companies that engage in them don't tend to last very long because no one really wants to use their service.
Like Linkedin? I know someone who recently joined is this is precisely what Linkedin did. So you say they won't last very long and no one wants to use their service? We'll see.
(reply to this comment) (link to this comment)
Tacking on attacks about privacy invasion and identity theft seems like bit much.
Identity theft, no, but how can you deny invasion of privacy? It seems pretty clear cut in that respect.
(reply to this comment) (link to this comment)
Fraud
In my recent article, I talk about the fact that online credit card theft often results in 600 hours of work on the victim’s part to fix the damage. Amazing isn’t it? What could you have done in those 600 hours?
(reply to this comment) (link to this comment)
Add Your Comment