Hearing of the Subcommittee on Crime, Terrorism and Homeland Security of the House Judiciary Committee - Privacy and Cybercrime Enforcement Act

Statement

Date: Dec. 18, 2007
Location: Washington, DC


Hearing of the Subcommittee on Crime, Terrorism and Homeland Security of the House Judiciary Committee - Privacy and Cybercrime Enforcement Act

REP. SCOTT: The subcommittee will now come to order. I'm pleased to welcome you today to the hearing before the Subcommittee on Crime, Terrorism, and Homeland Security on H.R. 4175, the Privacy and Cybercrime Enforcement Act of 2007. I'd like to thank the chairman of the full committee, Mr. Conyers, for introducing the bill with bipartisan support. The bill was introduced at the time by the chairman and ranking member of the committee and the subcommittee, and I'm pleased to have been working with Mr. Conyers in drafting it to provide effective tools for federal prosecutors and state and local law enforcement agencies to combat identity theft and other cybercrimes.

The act takes several important steps to protect American consumers from the dangers of identity theft. First, our bill provides for the victims of identity theft, provides them with the ability to seek restitution in federal court for the loss of time and money spent restoring their credit. Under current law, restitution of victims is only available to recover the direct financial costs of identity theft offenses, such as recovering funds from one of the authorized credit card charges.

But many identity theft victims incur other indirect costs, such as loss of wages due to time taken off from work to resolve credit disputes. Our bill amends the present law to make it clear that restitution orders may include an amount equal to the value of the victim's time spent addressing the actual or intended harm of the identity theft.

Second, the bill addresses urgent needs for agencies and companies to provide appropriate notification when they experience major breaches. The problems of data breaches remain a persistent and dangerous threat to Americans' privacy. For example, in 2006 there was a disclosure that a company had suffered a major computer breach involving up to 45 million credit and debit card records. The company knew about the breach. None of its customers were told about it until a month later. And we're all aware of the identity theft from 26 million of our veterans and active duty personnel from the Department of Veterans' Affairs last year.

Although up to 39 states have laws pertaining to data breaches, there's no federal standard or regulation to provide notice. Our bill will require rapid notice of breaches to the FBI and Secret service, and this notice is critical to the successful investigation and prosecution of any criminal activity associated with the breach. The FBI and Secret Service would then publish the list of reported breaches in the federal register so that the public will be aware of where and to what extent major data breaches are occurring.

Finally, the bill makes it a crime punishable by up to five years in prison for knowingly -- to fail to report major breaches to the appropriate authorities. Lastly, this bill provides much needed tools to federal and state law enforcement agents. The bill adds Section 1030 to the Computer Fraud and Abuse Act to the RICO statute, which will provide the Department of Justice with a much needed tool to investigate and prosecute organized crime syndicates, which use sophisticated cyber schemes to commit criminal acts.

The bill also authorizes $25 million for each of the fiscal years from 2008 to 2010 to establish state grant programs with enforcement of cyber crimes. State and local law enforcement resources need to be strengthened to attack the low lying identity theft that federal prosecutors fail to go after. We heard in the last Congress at a subcommittee hearing about the incident involving Senator Domenici where some $800 in merchandise was charged to his stolen credit card. We found that the crime was not being prosecuted.

So thieves are left with the knowledge that if they don't steal too much, they can do so with impunity. The credit card company will cancel the debt, write off the loss, and they'll be no criminal investigation. And so the thieves can keep the bounty of their crimes without worrying about prosecution. I believe that the Secret Service working in partnership with state law enforcement could quickly reverse this expectation that thieves have in this front.

H.R. 4175 is a comprehensive bill that not only deals with the need to provide law enforcement, notice the law enforcement when innocent consumers have their data breached, it also deals with the underlying problems of lack of accountability to deter crimes from occurring in the first place. Our privacy in cyber crimes lag behind both capabilities of our technology and the sophistication of identity thieves, and this legislation will close that gap.

It's now my pleasure to recognize our new ranking member of the subcommittee, the gentleman from Texas, Judge Gohmert.

BREAK IN TRANSCRIPT

REP. SCOTT: And without objection, other members will have the opportunity to include opening statements in the record at this point. And I want to thank the witnesses for your patience. Sometimes because of votes things -- the schedule just goes awry, and we appreciate your patience in remaining with us.

We have a distinguished panel of witnesses here today to help us consider important issues that are before us. The first witness is Andrew Lourie, who is the acting principle deputy assistant attorney general and chief of staff for the Criminal Division at the Department of Justice. He's currently serving a detail from the U.S. Attorney's Office from the southern district of Florida, where for the past five years he's served as managing the assistant U.S. attorney in the West Palm Beach office. He served two prior details at the department, both as chief of the Public Integrity Section.

The next witness is Craig Magaw, special agent in charge of the criminal investigative division, the United States Secret Service. He provides guidance in determining the investigative focus of the division, which provides direction to all Secret Service field offices. He is a 20-year veteran of the Secret Service, native of Columbus, Ohio. He received his Bachelor of Arts degree from the University of Maryland and a Masters degree in the field of management from John Hopkins University.

Next will be Joel Winston, the associate director of the Division of Privacy and Identity Protection at the Federal Trade Commission's Bureau of Consumer Protection. That division has a responsibility over consumer privacy and data security issues, identity theft, and credit reporting matters. Mr. Winston is currently serving on the federal government's Identity Theft Task Force, which was created by the President in March, 2006. Mr. Winston received his undergraduate and law degrees from the University of Michigan.

Next will be Jaimee Napp, executive director of the Identity Theft Action Council of Nebraska. He founded the council in 2006. Excuse me, she founded her -- she founded the council in 2006 to use her journey as an identity theft victim to help others. The council is the first nonprofit organization dedicated solely to identity theft issues, assisting victims in Nebraska. She received her Bachelor of Journalism from the University of Nebraska at Lincoln.

Next will be Robert Holleyman, president and CEO of the Business Software Alliance. Mr. Holleyman has headed the alliance since 1990 overseeing operations in more than 85 countries. He's widely known for his work on policy related issues affecting the technology industry, including intellectual property laws, cyber security, international trade, and electronic commerce. He earned his Bachelor of Arts degree in political science at Trinity University in Texas, and his -- (unintelligible) -- doctorate from Louisiana State University Law Center in Baton Rouge.

Finally, we have Lillie Coney, associate director of the Electronic Privacy Information Center in Washington, D.C. She serves as a coordinator for the Privacy Coalition. The Privacy Coalition has over 40 organizations and affiliates who share a commitment of freedom and privacy rights. She has testified before the Department of Homeland Security's Data Privacy and Integrity and Advisory Committee under domestic surveillance.

Now, each of our witnesses' written statements will be made part of the record in -- all of those statements in their entirety. I would ask that each witness summarize his or her testimony in five minutes or less. And to help you stay within that time, there's a timing device on your table that will start green, go to yellow when you have one minute left, and then finally, to red when your time has expired. We'll begin with -- and unfortunately, we're expecting a vote any minute now, so we'll go as far as we can, break for a vote, and then come right back.

Mr. Lourie.

BREAK IN TRANSCRIPT

REP. SCOTT: Thank you very much, Ms. Coney.

We'll now have questions from the members, and I recognize myself for five minutes at this time.

Mr. Lourie, Mr. Magaw, the Identify Theft Penalty Enhancement Act included $10 million authorized to track down identity thieves. What have you done with the money?

MR. LOURIE: We have been actively pursuing identify theft cases around the country, Chairman Scott. In the last -- between '05 and '06 identify theft cases alone increased about 22 or 23 percent from 1,500 and change to 1,900 and change. Many of those were under the Aggravated Identity Fraud Statute. Those numbers increased from 226 in '05 to 507 in '06.

In addition, there are -- the Secret Service and the FBI have been establishing task forces all over the country, joining together with their federal colleagues as well as local law enforcement and state law enforcement to attack identity crime at a local level and to ensure that as few of these cases as possible slip through the cracks.

REP. SCOTT: So you are putting the $10 million to good use?

MR. LOURIE: Yes.

REP. SCOTT: Did you run out of money?

MR. LOURIE: (laughs) I don't know if we ran out of money, but I can get back to you on that.

REP. SCOTT: Well, if you are tracking down cases with the money, do you have enough? The original -- when the bill -- one of the bills that the $10 million came out of -- the original bill had $100 million, and we were told by the administration that they didn't need any money, so we just left you -- where $10 million got left. It seems to me that this ought to be a high priority, and I think the committee -- maybe. I can't speak for the committee, but I'd be willing to put some more authority so that you could track down more thieves so that people would get the idea that they might get caught. Have you used up all of the $10 million so that we might consider increasing the authorization?

MR. LOURIE: As I sit here today, I can't tell you whether or not we've used up all the $10 million, and I'd be happy to work with the committee and get back to you on that.

REP. SCOTT: Okay, now, part of the -- if you have limited funds, you have to make decisions so that -- you know, the $5,000 threshold -- (everybody's ?) stealing this, and $5,000 is pretty much home free. What would it take -- how much would it take to get cases under $5,000 also on your target list?

MR. LOURIE: Well, I can't tell you how much it would take with respect to money, if that's your question, for prosecution offices, the U.S. attorneys offices around the country, to lower their thresholds, or if the Department would support that. I can tell you that we have used the money that we have had to create these regional task forces to work together closely with the state prosecutors offices and state law enforcement and to train them in the investigation and prosecution of these sorts of crimes, and it's --

REP. SCOTT: But the problem with these cases is they are, in fact, labor intensive because there's a lot of work that needs to be done. The information is there, but some of it might include -- when you find out that somebody with a stolen credit card has ordered something delivered to a post office box, you may have to have somebody sit out there until they come to pick it up, and that's -- you've got to pay for that. I mean, that's just the hourly rate so that -- most -- many of these cases can be solved if you just had the resources, and so we'll work together to find out what resources you may need to lower the threshold so if somebody gets the information, they may feel they have -- they're at risk of actually getting caught.

Now, if a database is breached, is mere possession of the database a crime?

MR LOURIE: It depends if it's knowing. If a database is breached and somebody extracts the information, then yes. If it's unauthorized extraction, it is a crime.

REP. SCOTT: Is buying a Social Security number from somebody a crime before you actually -- without using it?

MR. LOURIE.: I don't have the statutes in front of me, but I believe under Title 44, the Social Security Statute, that possession if it's with intent to commit fraud would be a crime.

REP. SCOTT: But mere possession -- if you buy a Social Security number and that's all you've got, you don't know what they were going to do with it --

MR. LOURIE: Well, it's fairly easy to prove that somebody who buys somebody else's Social Security if it's not their own intends to commit fraud with it. But the answer to your question is yes, if you could not prove that element, I believe that that would -- then you would not be able to satisfy the statute.

REP. SCOTT: Is fishing a crime?

MR. LOURIE: Phishing is a crime if it violates one of the statutes set forth in 1030, the elements, so --

REP. SCOTT: Do we need to make it clear that phishing is, in fact, a crime?

MR. LOURIE: No, Chairman Scott, I don't think it's necessary to necessarily change the language of the bill the way you have it now to indicate that phishing is itself a crime. The language that's set forth in the bill is adequate to capture those types of scams with the suggestions that we've set forth here today.

REP. SCOTT: Now, several people have mentioned whether or not just putting a cookie on somebody's computer where you can extract information without so-called damaging the computer -- is that not trespassing or some crime -- unauthorized placing of one of those cookies in somebody's computer so that you can get information? Isn't that some kind of crime today?

MR. LOURIE: Well, what I'd like to do is go back and get back to the committee on that question.

REP. SCOTT: Okay.

MR. LOURIE: Certainly, it sounds like a variation of botnet, the way you asked the question. But there are -- depending the way you analyze the statute and the various elements of the statutes, the intent of the person who puts it there is significant.

REP. SCOTT: I've heard the suggestion that it ought to be a crime if you do it to 10 computers. Is there any reason why if you do it to one computer why that also should not be a crime?

MR. LOURIE: Well, it may very well be a crime under various state statutes. What we are attempting to do is bring more crimes within the per view (ph) of the federal statute, not less.

REP. SCOTT: So we'll be working together on that. The gentleman from Texas.

BREAK IN TRANSCRIPT

REP. SCOTT: Thank you. And I want to thank all of our witnesses for their testimony. Members may have additional questions to ask, and we'll submit those to you in writing, and we'd appreciate it if you could respond as soon as possible so the answers can be part of the record. Without objection, the hearing record will remain open for one week for the submission of additional materials.

The chairman of the Commercial and Administrative Law Subcommittee has offered a statement. She has reminded us that some of the parts of the bill come under the jurisdiction of her subcommittee as well as most of it in this subcommittee. And so she has an interest in this legislation. Without -- the gentleman from Texas.

BREAK IN TRANSCRIPT


Source
arrow_upward