LENDERS COMPLIANCE GROUP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERSCORP | MISMO | NAMB

Showing posts with label CAN-SPAM. Show all posts
Showing posts with label CAN-SPAM. Show all posts

Thursday, August 13, 2020

Fair Housing Act – Advertising Violations

QUESTION
We had a Fair Housing Act examination recently by our state banking department and got hit with a citation for violations. This came as a real shock to us. 

 We have 30 days to fix the issues and also prove that we have done a thorough review of our advertising to look for potential Fair Housing violations. We only have one person in compliance – me! I have done a lot of research for this response. But this seems like an overwhelming task. 

So, I’m turning to you for some guidance. 

Are there some basic things I should be looking for in our advertising?

ANSWER
I recognize this may cause some pressure, but you’ll do fine as long as you undertake the review in a careful and procedural way. You need to produce a report that provides specimens of the advertisements (before and after revisions), the remedial actions taken with respect to those particular advertisements, and the advertising policies and procedures that your financial institution implements. 

My firm does advertising compliance reviews all the time and, if you need assistance, please contact me HERE. I’ll have your advertisements reviewed immediately by competent subject matter experts.

Keep in mind, advertising compliance draws on numerous interlocking regulations, Acts, Best Practices, rules, disclosure mandates, and so forth. A small mistake can get magnified quickly into a litigious class action issue, let alone a federal or state administrative action. So, make it your business to review each advertisement before it is published. Seek appropriate compliance support if there is a scintilla of doubt or uncertainty.

As to a consideration of things to be on the look out for, I would put the following on the list. Though it is not comprehensive, I think it serves to set the tone for further reviews on your part. 

And, as I said, contact me if you need further support. 

My comments are based on Fair Housing Act mandates.
  • Advertisements must include the equal housing logo a statement that you are an equal housing lender. In printed advertising, the logo must be no smaller than:
    • 1/2 page or larger ad (2 × 2 inches) 
    • 1/8 page up to 1/2 page ad (1 × 1 inch)
    • 4 column inches to 1/8 page ad (1/2 × 1/2 inch)
    • Less than 4 column inches (Need not use the logo, but must use the legend “Equal Housing Lender”) 
  • In any advertising other than printed advertising, the logo must be at least as large as any other logo used. If no other logo is used, then the fair housing logo must be clearly visible in boldface type or at least 3 percent of the advertisement should be devoted to a statement of the fair housing policy.
  • For oral advertising, you may satisfy the Fair Housing Act advertising requirement by stating that you are an “equal housing lender.”
  • When advertising is both verbal and visual, you should use either method (a visual logo or a spoken statement) to meet the requirement.
  • Each public office should prominently post an equal housing lender poster.
  • Advertising may not contain any words, symbols, models, or other forms of communication suggesting a discriminatory preference or policy of exclusion because of race, color, religion, national origin, sex, handicap, or familial status. When using models in advertising, you should use models from different racial groups.
  • You should avoid the following:
    • Words descriptive of a dwelling, landlord, or tenants, such as white private home, colored home, Jewish home, Hispanic residence, or adult building.
    • Words indicative of a prohibited basis, such as: 
— Race: Negro, Black, Caucasian, Oriental, American Indian.
— Color: White, Black, Colored.
— Religion: Protestant, Christian, Catholic, Jew.
— National Origin: Mexican American, Puerto Rican, Philippine, Polish, Hungarian, Irish, Italian, Chicano, African, Hispanic, Chinese, Indian, Latino.
— Sex: The exclusive use of words in advertisements (such as “he” or “she”), stating or tending to imply that the loans being advertised are available to persons of only one sex and not the other.
— Age: Senior citizens.
— Handicap: Crippled, blind, deaf, mentally ill, retarded, impaired, handicapped, physically fit.
— Familial Status: Adults, children, singles, mature persons.
  • Words and phrases used in a discriminatory context, such as “restricted.”
  • “Red light” words. Examples of “red light” words include “sports enthusiasts,” which could discourage the handicapped, and “quiet neighborhood,” which could be a code word for “no children.” 
  • Symbols or logotypes that imply or suggest race, color, religion, sex, handicap, familial status, or national origin.
  • Colloquialisms used regionally or locally that suggest race, color, religion, sex, handicap, familial status, or national origin.
  • You should avoid the selective use of advertising media or content, such as:
    • The use of the English language alone or the exclusive use of media catering to the majority population in an area, when non-English language or other minority media also are available.
    • The strategic placement of billboards, brochures distributed within a limited geographic area, or displays or announcements only available in selected branches.
    • The use of human models primarily in media that cater to one racial or national origin segment of the population without a complementary advertising campaign directed at other groups.
Be sensitive to the potential discriminatory effects of your marketing practices! For example, if you often focus on contacts with real estate agents and mortgage brokers as a primary marketing strategy to generate loan applications, you should be careful to include contact with minority real estate agents and loan brokers and other real estate agents and loan brokers serving predominantly minority areas.

Like the Equal Credit Opportunity Act, creditors under the Fair Housing Act may affirmatively solicit or encourage members of traditionally disadvantaged groups to apply for credit.

Jonathan Foxx, Ph.D., MBA
Chairman & Managing Director
Lenders Compliance Group

Thursday, August 6, 2020

COVID-19: Imposters and Money Mules

QUESTION

I am an attorney who handles compliance for a small bank here in the southeast. A customer came into our branch and indicated that a person claiming to represent a government agency contacted her by phone, followed up with email, and asked for bank account information to process an Economic Impact Payment.

Customers have told us about unsolicited communications from supposedly trusted sources or government programs related to COVID-19, instructing readers to open embedded links or files or to provide personal or financial information, including account credentials (i.e., usernames and passwords).

We even reported a SAR on a customer who made several atypical transactions involving an overseas account. When we asked about these transactions, the customer indicated they were for a person located overseas who needs financial assistance because of the COVID-19 pandemic.

I wonder if you would provide some possible scams relating to COVID-19. What are some illicit activities and consumer fraud schemes that are associated with COVID-19?

ANSWER

Most people want to obey the law. Unfortunately, there are plenty of bad actors who spend their time cooking up ways to defraud consumers. One set of responsibilities for a bank or nonbank is to detect, prevent, and report consumer fraud and other unlawful activities. COVID-19 has brought out the best and the worst in people, especially the worst of the worst: those who would stalk consumers to connive ways to filch their hard-earned assets amid a pandemic. Let’s face it, some people are just so broken that they don’t care about anyone but themselves. But everyone has a stake in a stable economy.

There has definitely been an increase in consumer fraud relating to COVID-19. I am going to briefly outline two types of fraudulent schemes: imposter scams and money mule schemes. Both of these deceptive tactics are described in your question.

Keep in mind that crooks are very creative. As soon as their scam is exposed, they come up with another way to commit fraud. So, even as I write a response, the bandits are continuing to find new ways to manipulate consumers, doing their illegal most to exploit vulnerabilities caused by the pandemic.

Imposter scams and money mule schemes happen where actors deceive victims by impersonating federal government agencies, international organizations, or charities. FinCEN has identified the financial red flag indicators to alert financial institutions to these frauds and to assist financial institutions in detecting, preventing, and reporting suspicious transactions associated with the COVID-19 pandemic. We have broadened our Anti-Money Laundering Program testing, policies, and training to include such red flags.

For AML compliance assistance, contact us HERE.

But no single financial red flag indicator is necessarily indicative of illicit or suspicious activity. Financial institutions should consider additional contextual information and the surrounding facts and circumstances. Such context-related information includes a customer’s historical, financial activity, whether the transactions are in line with prevailing business practices, and whether the customer exhibits multiple indicators. Various criteria should be considered before determining if a transaction is suspicious or otherwise indicative of potentially fraudulent COVID-19-related activities.

In other words, your review should be “risk-based,” ensuring compliance with the Bank Secrecy Act (BSA). Therefore, perform additional inquiries and investigations where appropriate. Unfortunately, some of the financial red flag indicators may apply to multiple COVID-19-related fraudulent activities. Given that many scammers are targeting customers as opposed to financial institutions directly, financial institutions should remain on the alert for potential suspicious activities when interacting with their customers,

Let’s discuss imposter scams first, and then follow with a discussion about money mule schemes. I have given you numerous footnotes to help you to train yourself, train your staff, and inform your customers. I will conclude with some guidance on completing the Suspicious Activity Report. You can always contact me if you want to discuss your compliance needs in detail. Contact me HERE.

Imposter Scams

In imposter scams, criminals impersonate organizations such as government agencies, non-profit groups, universities, or charities to offer fraudulent services or otherwise defraud victims. While imposter scams can take multiple forms, the basic methodology involves an actor who (1) contacts a target under the pretense of representing an official organization, and then (2) coerces or convinces the target to provide funds or valuable information, including engaging in behavior that causes the target’s computer to be infected with malware, or spreading disinformation.[i] In the case of schemes connected to COVID-19, imposters may pose as officials or representatives from the Internal Revenue Service (IRS),[ii] the Centers for Disease Control and Prevention (CDC),[iii] the World Health Organization (WHO), other healthcare or non-profit groups, and academic institutions.[iv]

Imposters defraud and deceive the vulnerable, including the elderly and unemployed, through the solicitation of payments (such as digital payments and virtual currency), donations, or personal information via email, robocalls, text messages,[v] or other communication methods. For instance, an imposter may contact potential victims by phone, email, or text to require that the victim must verify personal information or send payments to scammers in return for COVID-19-related stimulus payments or benefits, including Economic Impact Payments (EIP)[vi] under the Coronavirus Aid, Relief, and Economic Security (CARES) Act.[vii]

We have provided considerable information about EIPs in our free Checklist & Workbook, Business Continuity Plan, COVID-19 Pandemic Response (now on its Update # 7, with Update # 8 to be released soon). Get it HERE.

Another instance includes imposters contacting victims and posing as government or health care representatives engaged in COVID-19 contact tracing activities, implying that a victim must share personal or financial information as part of contact tracing efforts.[viii] I could give a host of multiple examples, including phishing schemes, where imposters send communications appearing to come from legitimate sources, to collect victims’ personal and financial data while potentially infecting their devices by convincing the target to download a malicious attachment or click malicious links.[ix]

Scammers may also impersonate legitimate charities or create sham charities, taking advantage of the generosity of the public and embezzling donations intended for COVID-19 response efforts.[x]

As to other communication methods, criminals often use social media accounts, door-to-door collections, flyers, mailings, telephone and robocalls, text messages, websites, and emails mimicking legitimate charities and non-profits to defraud the public. These operations may include words like “relief,” “fund,” “donation,” and “foundation” in their titles to give the illusion that they are a legitimate organization.[xi]

Money Mule Schemes

You may not have heard this term before. It’s a pretty nasty activity. A money mule is “a person who transfers illegally acquired money on behalf of or at the direction of another.”[xii] Money mule schemes, including those associated with the COVID-19 pandemic, span the spectrum of using unwitting, witting, or complicit money mules.[xiii] An unwitting or unknowing money mule is an individual who is “unaware that he or she is part of a larger criminal scheme.”

This crook is motivated by a host of reasons, most of them not worth mentioning.[xiv] A witting money mule is an individual who “chooses to ignore obvious red flags or acts willfully blind to his or her money movement activity.” The individual is motivated by financial gain or an unwillingness to acknowledge his or her role.[xv] A complicit money mule is an individual who is “aware of his or her role as a money mule and is complicit in the larger criminal scheme.” The individual is motivated by financial gain or loyalty to a criminal group.[xvi]

During the COVID-19 pandemic, U.S. authorities have been detecting recruiters using money mule schemes, such as good-Samaritan, romance, and work-from-home schemes.[xvii] In work-from-home schemes, for instance, COVID-19 money mule recruiters, under a false charity or company label, approach targets with a seemingly legitimate offer of employment under the pretense of work-from-home jobs, often through Internet or social media advertisements, emails, or text messages. Once the target accepts the “employment,” he or she receives instructions to move funds through accounts or to set up a new account in the target’s name for the bogus “business.” The target (i.e., the money mule) earns money by taking a percentage of the funds that he or she helps to transfer per the instructions of the bogus “employer.”[xviii]

U.S. authorities also have identified criminals using money mules to exploit unemployment insurance programs during the COVID-19 pandemic.[xix]

Thursday, October 4, 2018

Harvesting Electronic Mail


QUESTION
We hired a telemarketing and website lead company to get new loan applicant leads. In the company's contract, they state that they provide disclosure involving the “harvesting” of electronic mail. What is meant by harvesting?

ANSWER
As I have said many times, you should be retaining a firm such as ours to review your telemarketing policies. There are so many ways that a relationship with a telemarketer or a website used to generate leads can go wrong, that you really need a careful review of this kind of relationship.

However, it is important to know what “harvesting” means, especially as it relates to the services provided by a lead source. 

“Harvesting” refers to the process of obtaining the electronic mail address of a recipient. By "electronic mail address," I mean a destination, commonly expressed as a string of characters, consisting of a unique user name of mail box and a reference to an Internet domain, whether or not displayed, to which an electronic mail message can be sent. [15 USC § 7006(1)]

An "electronic mail message" is simply a message sent to a unique electronic mail address. [15 USC § 7006(2)]

Harvesting takes place by using an automated means from the Internet website or proprietary online service operated by another entity, and such website or online service included, at the time the address was obtained, a notice stating that the operator of such website or online service will not give, sell, or otherwise transfer addresses maintained by such website or online service to any other party for the purposes of initiating, or others to initiate, electronic mail messages. [15 USC § 7006(3)]

Jonathan Foxx
Managing Director
Lenders Compliance Group

Friday, September 8, 2017

Charging for an “Opt Out”

QUESTION
This is probably a strange question, but it came up in our review of the opt out procedures involving our CAN-SPAM policy. We would like to charge a fee when somebody does an opt out. We want certain requirements in place that a customer has to take, step by step, in order to opt out. So, can a customer be required to pay a fee? Can we require the customer to provide certain information or take some other steps in order to opt out? And what should we do once a customer makes a request to opt out?

ANSWER
The question is not as strange as you think! We actually come across this question sometimes when conducting website and marketing reviews.

To put it succinctly, a sender or any person acting on behalf of a sender may not require that any recipient, in order to exercise an “opt out” request pursuant to the Controlling the Assault of Non-Solicited Pornography and Marketing Act, known as CAN-SPAM, or have the request honored, (1) pay any fee, (2) provide any information other than the recipient’s electronic mail address and “opt out” preferences, or (3) take any other steps except sending a reply electronic message or visiting a single website page. [16 CFR § 316.5]

Once a recipient makes a request using the applicable “opt out” mechanism not to receive some or any commercial electronic mail messages from a sender, the sender may not initiate transmission to the recipient of a commercial electronic mail message covered by the request more than ten business days after receipt of the “opt out” request. [15 USC § 7704(a)(4)(i)]

Jonathan Foxx 
Managing Director 
Lenders Compliance Group

Thursday, February 5, 2015

CAN-Spam Preemption

QUESTION
Our bank’s compliance officer has the view that CAN-SPAM requirements preempt all state laws that are similar to it. Are there any instances where state law trumps CAN-SPAM?

ANSWER
CAN-SPAM preempts any statute, regulation, or rule of a state, or even a political subdivision of a state, that expressly regulates the use of electronic mail to send commercial messages – except to the extent that any such statute, regulation, or rule prohibits falsity or deception in any portion of a commercial electronic mail message or information attached thereto. [15 USC § 7707(b)(1)]

Thus, CAN-SPAM carves out an exception from preemption for state laws that govern the use of commercial email by prohibiting fraud or deception in messages or attachments.

CAN-SPAM does not preempt the applicability of (1) state laws that are not specific to electronic mail, including state trespass, contract or tort laws, or (2) state laws that relate to acts of fraud or computer crime. [15 USC § 7707(b)(2)]

State laws that are not specific to commercial email, but would apply to commercial email (together with other types of communication or activity), are not preempted; neither are state laws that address computer fraud or crime more generally.

Although not specific to mortgage banking, policies and procedures used by "internet access services" to block spam are also protected from preemption. Internet access services’ policies and procedures are preempted from CAN-SPAM with respect to declining to transmit, route, relay, handle, or store certain types of electronic mail messages. [15 USC § 7707(c)]

Questions as to which state anti-spam laws are preempted, and to what extent such laws are preempted, are ultimately answered through the legal interpretation of courts. So far, the issue of CAN-SPAM preemption has been addressed by three Federal Circuit Courts of Appeals: the Fourth Circuit, the Fifth Circuit, and the Ninth Circuit.

Jonathan Foxx
President & Managing Director
Lenders Compliance Group

Thursday, December 11, 2014

Violating CAN-SPAM: Misleading Headers

QUESTION
We were recently cited by our regulator for violations of CAN-SPAM. Specifically, the header of our email was considered to be misleading. How do we determine when a header is violating the CAN-SPAM requirements?

ANSWER
CAN-SPAM is the acronym for Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003. The Act governs the use of commercial email as a marketing tool as well as other activities relating to commercial email that is deemed to be abusive.

It is unlawful to initiate a transmission to a protected computer of a commercial electronic mail message, or a transactional or relationship message, that contains, or is accompanied by, header information that is materially false or materially misleading.

Generally, a “protected computer” is a computer used in interstate or foreign commerce or communication, including a computer located outside the United States that is used in a manner that affects interstate or foreign commerce or communication of the United States. [LVRC Holdings LLC v. Brekka, 581 F.3d 1127, 1131 (9th Cir. Nev. 2009)] Gradually this definition has been expanded to include all networked computers, inside the U.S. or outside. [Shurgard Storage Centers, Inc. v. Safeguard Self Storage, Inc., 119 FSupp2d 1121 (WD Wash 2000)] Briefly put, computers on the Internet are “protected computers.” [US v. Fowler, Case No. 8:10-cr-65-T-24 AEP (MDFL Oct. 25, 2010)]

Header information is considered materially misleading if the header:

1. Is technically accurate but includes an originating electronic mail address, domain name, or Internet Protocol address the access to which for purposes of initiating the message was obtained by means of false or fraudulent pretenses or representations; and,

2. Fails to identify accurately a protected computer used to initiate the message because the person initiating the message knowingly uses another protected computer to relay or retransmit the message for purposes of disguising its origin. [15 USC § 7704(a)(1)(A), (C)]

Furthermore, CAN-SPAM prohibits initiating a transmission of a commercial electronic mail message to a protected computer if there is actual knowledge, or knowledge fairly implied on the basis of objective circumstances, that a subject heading of the message would be likely to mislead a recipient, acting reasonably under the circumstances, about a material fact regarding the contents or subject matter of the message. [15 USC § 7704(a)(2)] 

Jonathan Foxx
President & Managing Director
Lenders Compliance Group

Thursday, August 7, 2014

Email Advertising: CAN-SPAM Compliance


QUESTION 
I am aware of the “do not call’ list, but is there a similar type of “do not email” list?  Also, what regulations do we need to be aware of if we choose to solicit business via email?

ANSWER 
There is no email equivalent to the federal “do not call” list, yet there are federal rules set forth in the CAN-SPAM Act that must be adhered to when a commercial message or advertisement is transmitted via email. [“CAN-SPAM” is a nickname for Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003 (15 USC Chapter 103).]

The CAN-SPAM Act covers all commercial messages defined as “any electronic mail message the primary purpose of which is the commercial advertisement or promotion of a commercial product or service” [See Section 3(2) of the Act] Unlike many other advertisement regulations, the CAN-SPAM Act does not contain an exception for business to business emails. 

     Below is a summary of the important CAN-SPAM requirements:
  1. Opt-Out/Unsubscribe Requirement [Section 5(a)(5)] – The email must contain a clear and conspicuous explanation detailing a mechanism for the recipient to opt out of all future emails. All opt-out requests must be honored within 10 business days. The only information recipients can be asked to provide, in order to opt out of future emails, is their email addresses. 
  2. No ghost emails permitted – A valid physical address of the sender of the message and/or the advertiser must be set forth in the email [Section 5(a)(5)]. 
  3. Be transparent [Section 5] – (a) the email must clearly and conspicuously indicate it is an advertisement; (b) the subject line must relate to the body of the email and not be deceptive; and, (c) the “from” header must be accurate and identify the sender on the email.
In addition to some violations of the CAN-SPAM Act being deemed criminal offenses, each separate email in violation of the Act subjects the sender of the email to statutory and actual damages as well as attorney’s fees.

In sum, you need to make sure that all email solicitations comply with the CAN-SPAM Act, because an email blast which fails to comply with the CAM-SPAM Act could result in substantial economic damage to a mortgage lender.

Michael Barone
Director/Legal & Regulatory Compliance
Lenders Compliance Group