<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[The Breach Blog]]></title>
    <link>http://securityratty.com/feed/ed372254c847b4d675176cbfd7130e92</link>
    <description></description>
    <pubDate>Wed, 07 May 2008 18:20:50 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Oklahoma State University Parking Services server is compromised]]></title>
      <link>http://securityratty.com/article/f74dd3d54ef8465c68b7797c38075517</link>
      <guid>http://securityratty.com/article/f74dd3d54ef8465c68b7797c38075517</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
5/14/08

Organization
Oklahoma State University (&quot;OSU

Contractor/Consultant/Branch
OSU Parking &amp; Transit Services

Victims
OSU faculty, staff and...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/okstate.jpg" align="right" height="127" width="198"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>5/14/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://osu.okstate.edu/">Oklahoma State University ("OSU")</a>&nbsp; <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.parking.okstate.edu/">OSU Parking &amp; Transit Services</a> <br><br><span style="font-weight: bold;">Victims:</span><br>OSU faculty, staff and students who had purchased a parking permit between July 2002 and March 2008<br><br><span style="font-weight: bold;">Number Affected:</span><br>as many as 70,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, addresses and Social Security numbers"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"Oklahoma State University has discovered that a server under the control of OSU Parking and Transit Services had been accessed from another country without authorization. The database contained confidential information, specifically the names, addresses and Social Security numbers of OSU faculty, staff and students who had purchased a parking permit between July 2002 and March 2008."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://idalert.okstate.edu/incident_00003.html">Oklahoma State University Alert</a> <br><a href="http://www.koco.com/news/16267153/detail.html">KOCO Channel 5 News</a> <br><a href="http://ocolly.com/2008/05/15/student-faculty-and-staff-info-exposed-in-osu-parking-server-breach/">The Daily O'Collegian</a> <br><a href="http://newsok.com/osu-admits-computer-security-breach/article/3243594/?tm=1210801442">The Oklahoman</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Oklahoma State University<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>STILLWATER, Okla. -- Personal information belonging to anybody who got a parking pass at Oklahoma State University over the last five years has been compromised, university officials said Wednesday.<br><br>Oklahoma State University has discovered that a server under the control of OSU Parking and Transit Services had been accessed from another country without authorization. The database contained confidential information, specifically the names, addresses and Social Security numbers of OSU faculty, staff and students who had purchased a parking permit between July 2002 and March 2008.<br><span style="font-style: italic;">[Evan] What does the OSU Parking and Transit Services department need Social Security numbers for?&nbsp; Do you suppose information security personnel knew that sensitive personal information was stored on the server prior to this incident?</span><br><br>Upon discovering this intrusion, the IT Information Security Office immediately removed the server from the network to evaluate server activity to ascertain if personal information had been accessed.<br><br>The confidential information has been removed from the database.<br><br>The illegal access was limited to the parking and transit server.<br><br>As a result of its investigation, OSU believes the intruder's purpose and only action was to use the OSU server for storage capacity and bandwidth to upload and distribute illegal and inappropriate content.<br><span style="font-style: italic;">[Evan] I wonder if I am getting this right.&nbsp; Was there a direct network path from the public Internet through a firewall to the compromised database server running http, ftp, or some other file transfer protocol?&nbsp; That's not cool.&nbsp; A database server storing confidential information should not be accessible from the internet directly through a firewall. It is generally a good practice to separate the database function from the file transfer function into different servers and different firewall DMZs.&nbsp; All this for parking?&nbsp; Ugh.</span><br><br>OSU contacted and worked with federal law enforcement authorities.<br><br>After evaluation of all available data related to this incident, OSU found no evidence which would indicate that the database was copied or viewed by the hacker; however, OSU cannot say with 100 percent certainty that the hacker did not access personally identifiable information.<br><span style="font-style: italic;">[Evan] I wonder what evidence they looked for and how they went about gathering it.</span><br><br>We are not aware of any instances of misuse of this information or of any identify theft as a result of the temporary availability of this information.<br><br>OSU recommends you carefully review any bills or financial transactions you receive in the near future to ensure that the charges associated with your accounts are accurate.<br><span style="font-style: italic;">[Evan] Yeah!&nbsp; Review your bills (pay them occasionally) and financial transactions carefully.&nbsp; But wait, you do this already?&nbsp; Disappointing statement coming from an organization that did not carefully review their controls in securing your personal information.</span><br style="font-style: italic;"><br>OSU President Burns Hargis said, "This breakdown in security is totally unacceptable. We are conducting a full review and will take whatever steps are necessary to protect our network from unauthorized access. This is a serious matter and we will deal with it aggressively. We regret the circumstances and concern this situation has caused."<br><span style="font-style: italic;">[Evan] This is my favorite statement from this story!&nbsp; What do you suppose his stance was prior to being notified of the breach?&nbsp; </span><br><br><span style="font-style: italic;">In my experience, there are primarily ("primarily" because there are always exceptions) four types of senior information security management.&nbsp; You have the organizations that just don't get it and don't really care or know that they don't get it.&nbsp; These organizations lose information over and over and dangerously continue to operate in a business as usual manner. </span><br style="font-style: italic;"><br style="font-style: italic;"><span style="font-style: italic;">Secondly, you have the organizations that didn't get it, suffer some adverse event, then HOLY &amp;$#^!&nbsp; They respond with all guns blazing and overspend on controls they don't need and run a very cost ineffective security program (I guess they really never got it either).&nbsp; </span><br style="font-style: italic;"><br style="font-style: italic;"><span style="font-style: italic;">Thirdly, there is the company that didn't get it, suffered an adverse event and admitted they have a problem.&nbsp; These companies may seek guidance and consultation in the effort to build a comprehensive information security program.&nbsp; These programs should be built around business objectives and sound risk management.&nbsp; </span><br style="font-style: italic;"><br style="font-style: italic;"><span style="font-style: italic;">Lastly, there are the companies that were proactive and built a sound information security program because it was good business.&nbsp; These organizations didn't need an adverse event or breach before taking action.&nbsp; These organizations don't panic when an adverse event occurs.&nbsp; They know that eventually an adverse event will occur and they will be prepared when it does.</span><br style="font-style: italic;"><br>The server is believed to have been compromised on November 23, 2007. OSU learned of the breech [sic] on March 20, 2008 and blocked access to the server immediately.<br><span style="font-style: italic;">[Evan] Wow.&nbsp; The server was 0wn3d (like my 1337 5p34k?) for almost 4 months before anyone noticed?!&nbsp; That is way, way, way too long for a compromised server to go unnoticed.&nbsp; We can now assume that there was no effective IDS/IPS (host or network) and no effective logging and monitoring of the server.</span><br><br>The OSU Parking Department has altered their procedures for the collection of private information. Additionally, the server which was located at the OSU Parking Service's office will be relocated to the IT Data Center for enhanced security. OSU is conducting a full review and will be taking additional steps to protect our network from unauthorized access.<br><span style="font-style: italic;">[Evan] It's a very good idea to not collect private information if it is not required.&nbsp; It's too bad that it took a breach for this to happen.&nbsp; Moving the server from the Parking Service's office to the IT Data Center will help protect against physical security attacks, but this was a logical attack.&nbsp; Maybe the IT Data Center has better firewalls or something <img src="http://breachblog.com/emoticons/smile.png" border="0" />.&nbsp; I like the "full review".&nbsp; This should be done no less than annually.</span><br><br>The IT Information Security Office has made security recommendations to the OSU Parking Office which include physical relocation of their server and database to a more secure location, additional training for server administrators, and added vulnerability assessments.<br><br>Q. How will I know if any of my personal information was used by someone else? <br>A. The best way to find out is to obtain your credit reports from the three major credit bureaus: Equifax, Experian and Trans Union. If you notice accounts on your credit report that you did not open or applications for credit ("inquiries") that you did not make, these could be indications that someone else is using your personal information, without your permission.<br><span style="font-style: italic;">[Evan] "If you notice accounts on your credit report that you did not open or applications for credit ("inquiries") that you did not make", then chances are you have <span style="font-weight: bold;">already</span> become an identity-theft victim.&nbsp; I'm not saying whether this is likely, or not.</span><br><br>Q. Why did you have my personal information? <br>A. You provided this information to us when you applied to Oklahoma State University, or during your tenure as a student or employee here. Oklahoma State, like other institutions, maintains records of all employees and students who have attended the University.<br><span style="font-style: italic;">[Evan] Great question!&nbsp; Why did you have my personal information (on a publicly accessible server used in a department that doesn't really need it without proper protections and without proper monitoring)?</span><br><br><span style="font-weight: bold;">Commentary:</span><br>This breach torques me a little, in case you didn't pick up on that from the comments above.&nbsp; I made plenty.<br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/05/15/okstate.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Thu, 15 May 2008 11:08:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/server">server</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/server administrators">server administrators</category>
      <category domain="http://securityratty.com/tag/server immediately">server immediately</category>
      <category domain="http://securityratty.com/tag/server prior">server prior</category>
      <category domain="http://securityratty.com/tag/database server">database server</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <source url="http://breachblog.com/2008/05/15/okstate.aspx">Oklahoma State University Parking Services server is compromised</source>
    </item>
    <item>
      <title><![CDATA[Two students access confidential Dominican University files]]></title>
      <link>http://securityratty.com/article/c911429366b51bc32cae40fcf5414be0</link>
      <guid>http://securityratty.com/article/c911429366b51bc32cae40fcf5414be0</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
5/8/08

Organization
Dominican University

Contractor/Consultant/Branch
None

Victims
Students

Number Affected
5,215

Types of Data
names, addresses,...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/dominican.jpg" align="right" height="68" width="199"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>5/8/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.dom.edu/">Dominican University</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Students<br><br><span style="font-weight: bold;">Number Affected:</span><br>5,215<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, addresses, phone numbers, birthdays and Social Security numbers"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"CHICAGO -- Some Dominican University students and alumni were notified this week of a breach in security that could have put their personal information at risk.&nbsp; The university said two students were able to access records on a staff network storage area in April. The files were three spreadsheets from 2003, 2005 and 2007."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.nbc5.com/news/16205384/detail.html">WMAQ NBC Channel 5 News</a> <br><a href="http://www.pioneerlocal.com/riverforest/news/948729,RF-Security-051408-sl.article">RiverForest-Leaves</a> <br><a href="http://www.dom.edu/security/">Dominican University</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Dominican University<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Dominican University takes information security very seriously. In April, we discovered that two student workers had accessed Excel files containing limited student data by misusing passwords related to their work-study employment.<br><br>Two computer science sophomores who had password access through their work-study employment discovered three Excel files, containing a total of 5,215 student records.<br><br>These files were in an unsecure location that was to be accessible only to specific staff members.<br><span style="font-style: italic;">[Evan] Is this password misuse or just poorly secured files and poor security?&nbsp; The confidential files were stored in an unsecure location that was supposed to be accessible by specific staff.&nbsp; Does this make any sense to you?</span><br><br>One of the students came forward earlier this month with the information that they had accessed files that were to be available to staff only. The students then disclosed the full extent of their access to the exposed data and demonstrated to the administration how the access occurred.<br><span style="font-style: italic;">[Evan] I wonder if the school would have ever found out if the student didn't come forward.&nbsp; My guess is not.</span><br><br>We notified all affected parties in writing, set up a toll-free hotline, and have worked closely with both the local police and states attorney’s offices.<br><br>A letter was sent to all affected students and alumni on April 18 when the extent of the exposure could be determined.<br><br>The students went through a full university judicial process, were suspended temporarily and have been barred from future campus employment, among other sanctions.<br><br>The students are expected to return to classes next fall "under a lot of supervision, as you'd expect,"<br><span style="font-style: italic;">[Evan] I don't know.&nbsp; There are probably students doing worse things on campus that probably need a lot more supervision than these two.&nbsp; Judging only by what I have read, these students seem to have been pretty honest.&nbsp; They came forward, they cooperated with the investigation and even demonstrated what they did.&nbsp; </span><br><br>The university is conducting a complete security audit and internal review.<br><span style="font-style: italic;">[Evan] This should be done a regular basis anyway.&nbsp; All good information security programs conduct regular audits, assessments and reviews.</span><br><br>Dominican has conducted a complete internal security audit and has hired an external consultant to review all security processes.<br><span style="font-style: italic;">[Evan] I endorse the school's decision to enlist a third-party consultant, assuming that the consultant is good at what they do.&nbsp; The last statement contained the word "conducting", this statement contains "conducted".</span><br><br>At this time we have no reason to believe that any information has been misused, but retain the right to prosecute as necessary.<br><br>"Steps have been taken to make something like this more difficult to do in the future. We've significantly tightened security,"<br><span style="font-style: italic;">[Evan] If I had a dime for every time I heard this, I could retire very comfortably. If there are no details or facts to support statements like this, they don't mean much to me</span><br><br>If I have more questions, who should I call? You can call our toll-free number: (877) 387-8310.<br><br><span style="font-weight: bold;">Student Reaction:</span><br>"I was a little upset. I was nervous. I didn't know what to do. I knew that our family's been affected by this before, so I wanted to react right away,"<br><br>"I think that's crazy, because ... people can get your information, know things about you (and) you can't do anything about it,"<br><br>"Someone actually just charged on my debit card something. (It was) unrelated to this, I think, but it freaks me out every day now,"<br><span style="font-style: italic;">[Evan] This student didn't just buy some </span><a style="font-style: italic;" href="http://breachblog.com/2008/05/07/adobe.aspx">Adobe</a><span style="font-style: italic;"> education version software, did he/she?</span><br><br><span style="font-weight: bold;">Commentary:</span><br>I'm not sure if I am reading this right or not, but it seems almost like these students stumbled upon the confidential files and informed officials of their findings.&nbsp; I don't sense an dishonesty on their part.&nbsp; I could be wrong, but it also seems like the school didn't (and maybe still doesn't) properly secure confidential information.&nbsp; The statement about a secure file in an unsecured location is puzzling.<br><br>If assumptions are correct, then it may be ill-advised to sanction these students.&nbsp; Does anyone else see this the same way, or would you say that I am off base here?<br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/05/14/dominican.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Wed, 14 May 2008 18:40:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/university">university</category>
      <category domain="http://securityratty.com/tag/dominican university">dominican university</category>
      <category domain="http://securityratty.com/tag/dominican university students">dominican university students</category>
      <category domain="http://securityratty.com/tag/dominican">dominican</category>
      <category domain="http://securityratty.com/tag/students">students</category>
      <category domain="http://securityratty.com/tag/files">files</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security processes">security processes</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <source url="http://breachblog.com/2008/05/14/dominican.aspx">Two students access confidential Dominican University files</source>
    </item>
    <item>
      <title><![CDATA[HSBC loses a server in branch renovation]]></title>
      <link>http://securityratty.com/article/dea4cb8188870bfad6891526dcfee0f2</link>
      <guid>http://securityratty.com/article/dea4cb8188870bfad6891526dcfee0f2</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
5/7/08

Organization
Hong Kong and Shanghai Banking Corporation (&quot;HSBC

Contractor/Consultant/Branch
Kwun Tong branch

Victims
Customers

Number...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/hsbc.jpg" align="right" height="47" width="154"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>5/7/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.hsbc.com.hk/1/2/home">Hong Kong and Shanghai Banking Corporation ("HSBC")</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br></font><font size="2"><a href="http://www.banking.hsbc.com.hk/script/regional/launched/locator/locator.asp">Kwun Tong branch</a>&nbsp; </font><br><font size="2"><br><span style="font-weight: bold;">Victims:</span><br>Customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>159,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>"name, account number and transactions of customers"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"HONG KONG, May 8 (Xinhua) -- The Hong Kong branch of banking giant Hongkong and Shanghai Banking Corporation Limited (HSBC) has lost a computer server with client data involving about 159,000 accounts, the bank confirmed on Wednesday."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://news.idg.no/pcw/art.cfm?id=CDE0B1D6-17A4-0F78-318AEBF2087563C2">IDG Magazines Norge</a> <br><a href="http://news.xinhuanet.com/english/2008-05/08/content_8126223.htm">Xinhua News Agency</a> <br><a href="http://www.thestandard.com.hk/news_detail.asp?pp_cat=12&amp;art_id=65593&amp;sid=18831850&amp;con_type=3">The Standard</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>The Breach Blog was notified by an anonymous tip at 11:15AM on May 7th.&nbsp; It just took me a while to get it posted.&nbsp; Sorry for the delay!<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>HSBC has admitted losing a server containing data on 159,000 customers.<br><span style="font-style: italic;">[Evan] How do you lose a server?</span><br><br>The server went missing on 26 April from its Kwun Tong district branch in Hong Kong during renovation work<br><br>The server held customer names, account numbers, transaction amounts and transaction types<br><br>HSBC said the server is protected by "multiple layers of security" and the risk of data breaches and fraud is "deemed to be low".<br><span style="font-style: italic;">[Evan] What kind of "multiple layers of security"?&nbsp; This is one of those statements that is misused and overused.&nbsp; Without details, who knows what they are talking about.</span><br><br>the server contained no PIN codes or online banking login credentials.<br><br>The bank said it has reported the incident to the police, the Hong Kong Monetary Authority, and the Hong Kong privacy commissioner.<br><br>The case has been classified as theft.<br><span style="font-style: italic;">[Evan] Ah, so HSBC didn't really "lose" the server?&nbsp; It was stolen.</span><br><br>The Monetary Authority has demanded that the bank contact all the affected customers and explain what measures could be taken to avoid potential losses thereof.<br><br>The bank is contacting customers, who will not be liable for any financial loss arising from any fraudulent activity as a result of the lost data.<br><br>Clients data are kept in a confidential manner. If any complaint arises, we will deal with it case by case, HSBC chairman Vincent Cheng Hoi-chuen said.<br><br>Internet Society chairman Charles Mok Nai-kwong said even though the server has been encrypted, there may still be ways to access the data. <br><span style="font-style: italic;">[Evan] Charles Mok Nai-kwong states that the server was encrypted.&nbsp; This is a good thing.</span><br><br>"I do not know how advanced the system is or the skill of those who want to access the data. But if the server goes to the police, they will have ways to get the data," Mok said.<br>[Evan] This reminds me of a few stories I have read where authorities were unable to break commercially available encryption implementations.&nbsp; The one case that comes to mind was the case of the FBI <a href="http://www.pcworld.com/article/id,110841-page,1/article.html">unable to crack PGP</a> encrypted PDAs captured from terrorists.&nbsp; If the encryption was implemented correctly and key management is sound, it would be very difficult for the police to access meaningful information.<br><br><span style="font-weight: bold;">Commentary:</span><br>What type of physical controls were present at the time of the server theft?&nbsp; Stuart King on his ComputerWeekly <a href="http://www.computerweekly.com/blogs/stuart_king/2008/05/hsbc-lose-a-server.html">Risk management blog</a> sums this up very well when he says "Spend all you want on boxes of tricks to stop the hackers getting in, but forget to lock the door to the servers and it's game over."<br><br>The last HSBC breach that we reported on The Breach Blog was also physical security related, see below.<br><br><span style="font-weight: bold;">Past Breaches:</span><br>February, 2008 - <a href="http://breachblog.com/2008/02/06/hsbc.aspx">Five-year-old wanders into bank branch after-hours</a></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/05/14/hsbc.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Wed, 14 May 2008 12:16:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/server">server</category>
      <category domain="http://securityratty.com/tag/hsbc">hsbc</category>
      <category domain="http://securityratty.com/tag/server theft">server theft</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/lost data">lost data</category>
      <category domain="http://securityratty.com/tag/computer server">computer server</category>
      <category domain="http://securityratty.com/tag/data breaches">data breaches</category>
      <category domain="http://securityratty.com/tag/clients data">clients data</category>
      <category domain="http://securityratty.com/tag/hong kong">hong kong</category>
      <source url="http://breachblog.com/2008/05/14/hsbc.aspx">HSBC loses a server in branch renovation</source>
    </item>
    <item>
      <title><![CDATA[Technical glitch blamed in The Princeton Tower Club breach]]></title>
      <link>http://securityratty.com/article/15351609f42234c5774ba9e03af7e8e7</link>
      <guid>http://securityratty.com/article/15351609f42234c5774ba9e03af7e8e7</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
5/8/08

Organization
The Princeton Tower Club

Contractor/Consultant/Branch
None

Victims
Former club members

Number Affected
103

Types of Data
names...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/tower.jpg" align="right" height="70" width="200"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>5/8/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.princeton.edu/%7Etower/Update2006/main/">The Princeton Tower Club</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Former club members<br><br><span style="font-weight: bold;">Number Affected:</span><br>103<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names and social security numbers"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"Tower Club is taking steps to protect 103 of its alumni in the classes of 2006 and 2007 after a spreadsheet listing their names and social security numbers was e-mailed to current club members early Wednesday morning."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.dailyprincetonian.com/2008/05/09/21173/">The Daily Princetonian</a> <br><a href="http://www.upi.com/NewsTrack/Top_News/2008/05/10/princeton_club_accidentally_exposes_alumni/8122/">United Press International</a> <br><a href="http://www.app.com/apps/pbcs.dll/article?AID=/20080510/NEWS03/805100392/1007/NEWS03">Asbury Park Press</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Rachel Dunn and Josephine Wolff, The Daily Princetonian<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Tower Club is taking steps to protect 103 of its alumni in the classes of 2006 and 2007 after a spreadsheet listing their names and social security numbers was e-mailed to current club members early Wednesday morning.<br><br>The document was attached to an apparently unrelated e-mail that informed current members about a club event.<br><br>The spreadsheet was attached unintentionally because of "a technical glitch," Tower graduate board chair Greg Berzolla ’87 said<br><span style="font-style: italic;">[Evan] Really?&nbsp; A technical glitch?&nbsp; These types of breaches are usually the result of human error.</span><br><br>"The [spreadsheet] file wasn’t even available on the hard drive [of the computer that sent the e-mail]," Berzolla said. "[The e-mail system] took an old e-mail and used it as a template [for Wednesday’s e-mail] as near as we can guess. It’s not a system very many people use or understand, that’s the problem."<br><br>"I cannot comment on [the glitch] because I don’t understand it," he said. "I didn’t figure it out, I think the club technical chair [did]. [Tower president] Stephanie [Burset ’09] tried to explain it to me, but I think she doesn’t really understand it either."<br><span style="font-style: italic;">[Evan] At least he is honest.</span><br><br>Burset said in an e-mail that Pine, the e-mail system Tower currently uses, is "fairly antiquated, but our tech chairs have assured me that nothing like this can ever happen again," and added that "we plan on switching to a new client whom is more secure and easier to use."<br><span style="font-style: italic;">[Evan] I am concerned by statements like "nothing like this can ever happen again".&nbsp; We still don't know why it happened in the first place.</span><br><br>The e-mail was sent by Tower officers from the tower@princeton.edu account to the roughly 200 current club members.<br><br>Tower officers sent another e-mail to the club yesterday asking members to delete the message from their mailboxes "out of respect for ’07."<br><br>Berzolla said he believes the risk of identity fraud is "extremely limited"<br><br>"It’s hard for any kind of fraud to occur that quickly," he said of the incident. "I feel confident that our club members are not going to use this information badly."<br><span style="font-style: italic;">[Evan] It only takes one person.&nbsp; It should also be mentioned that one or more of the destination email accounts could be a shared account and that these emails were sent in clear text (subject to the possibility of interception).</span><br><br>"[The breach] would have had to have been intentional [for there to be legal repercussions]," Berzolla said.<br><span style="font-style: italic;">[Evan] Do you have to demonstrate intent to argue negligence (The failure to use reasonable care)?&nbsp; I'm certainly not a lawyer, but I think that there are cases where victims have been awarded damages when there was not intent to harm on the part of the defendant.&nbsp; I don't really advocate lawsuits anyway, but I am just stating what seems obvious to me.</span><br><br>Tower will pay for an identity theft protection services for the affected individuals next year.<br><br>Berzolla hopes this measure will assuage any possible threat of legal action from former members against the club. "I don’t expect there to be any problems, but just in case," he said.<br><br>The social security numbers on the spreadsheet were collected as part of the process of signing in new members several years ago, Berzolla said. Tower no longer requires its members to submit their social security numbers, he added.<br><span style="font-style: italic;">[Evan] It is a good practice to not collect information that isn't required to conduct business.&nbsp; The Tower Club would be well advised to go through the information they currently possess and purge the information they no longer need.</span><br><br><span style="font-weight: bold;">Victim Reaction:</span><br>"I had no idea this happened, and frankly, I’m baffled and a little pissed off," Valerie McConnell ’07 said<br><br>"Now that I know that the social security numbers weren’t sent out on purpose, I’m not pissed off," McConnell said. "I think my identity is ok. I can’t imagine anyone in the club trying to steal my identity (not that there’s a lot to steal right now anyway)."<br><span style="font-style: italic;">[Evan] I think I would still be pissed off.&nbsp; Identity thieves are not all stupid.&nbsp; Many of them will hold on to the information for a year or more before using it or selling it.</span><br><br>"[The incident] is a mistake; it shouldn’t have happened," Beylin said in an e-mail. "However, with the number of times I’ve handed out my SSN this year while seeking financial services or apartment hunting, it’s really not my biggest source of concern for identity theft."<br><span style="font-style: italic;">[Evan] This is a good point.&nbsp; Have you ever thought of all the times you have given out your Social Security number?&nbsp; All of your employers, schools, insurance companies, banks, mortgage companies, credit card companies, etc. have your number.&nbsp; The same number used for identification and authentication.&nbsp; A recipe for disaster?</span><br><br><span style="font-weight: bold;">Commentary:</span><br>The Tower Club does not handle personal information any worse than most other organizations.&nbsp; It seems like they just didn't know any better.&nbsp; It sometimes makes me nervous. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/05/13/tower.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 13 May 2008 05:20:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/princeton tower club">princeton tower club</category>
      <category domain="http://securityratty.com/tag/tower club">tower club</category>
      <category domain="http://securityratty.com/tag/club">club</category>
      <category domain="http://securityratty.com/tag/club technical chair">club technical chair</category>
      <category domain="http://securityratty.com/tag/e-mail system tower">e-mail system tower</category>
      <category domain="http://securityratty.com/tag/e-mail system">e-mail system</category>
      <category domain="http://securityratty.com/tag/tower">tower</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/current club">current club</category>
      <source url="http://breachblog.com/2008/05/13/tower.aspx">Technical glitch blamed in The Princeton Tower Club breach</source>
    </item>
    <item>
      <title><![CDATA[Former employee exposes Purdue Pharma personal information]]></title>
      <link>http://securityratty.com/article/5567080eb516a43807499e1350da7025</link>
      <guid>http://securityratty.com/article/5567080eb516a43807499e1350da7025</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
4/14/08 (delayed

Organization
Purdue Pharma L.P

Contractor/Consultant/Branch
None

Victims
Employees

Number Affected
5,000

Types of Data
names, dates...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/purdue.jpg" align="right" height="58" width="151"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>4/14/08 (delayed)<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.purduepharma.com">Purdue Pharma L.P.</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Employees<br><br><span style="font-weight: bold;">Number Affected:</span><br>~5,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, dates of birth, Social Security numbers and other pension related information"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"a former employee accessed a disk containing personal information about individuals employed by Purdue Pharma and its associated U.S. companies prior to December 31, 2003 and attempted to email some of the information on the disk to another person"<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://doj.nh.gov/consumer/pdf/purduepharma.pdf">The New Hampshire State Attorney General breach notification</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>The New Hampshire State Attorney General<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>We are writing to inform you about an incident affecting information maintained by Purdue Pharma L.P. ("Purdue Pharma")<br><br>Purdue Pharma is a privately held pharmaceutical company.<br><br>we recently learned that a former employee accessed a disk containing personal information about individuals employed by Purdue Pharma and its associated U.S. companies prior to December 31, 2003 and attempted to email some of the information on the disk to another person.<br><span style="font-style: italic;">[Evan] Attempted?&nbsp; What prevented the former employee from actually sending the information?&nbsp; It's not clear why the former employee wanted to send the information either.</span><br><br>We have determined that the disk contained information concerning approximately 5,000 individuals, and included names, dates of birth, Social Security numbers and other pension related information.<br><br>The former employee retained the disk when his employment ended, in direct violation of our policies and standard confidentiality agreement.<br><span style="font-style: italic;">[Evan] This former employee may not have given a damn.</span><br><br>As soon as we learned of the unauthorized access, we promptly demanded that the information be deleted and returned to us.<br><br>The original disk has been returned and we believe that all copies of the information have been deleted.<br><span style="font-style: italic;">[Evan] Once information confidentiality has been compromised it is very difficult (some would argue impossible) to restore it.&nbsp; How can you be certain that the information has been deleted?</span><br style="font-style: italic;"><br>We have undertaken a thorough investigation of this matter and, based on results of that investigation to date, we have no reason to believe that the personal information was misused.<br><span style="font-style: italic;">[Evan] Actually, there is EVERY reason to believe that the personal information was misused!&nbsp; If the information was used in a manner that was not permitted by the owner (the victim), then it was misused.&nbsp; That’s my definition anyway.</span><br style="font-style: italic;"><br>We are continuing to investigate the incident and are examining the measures we can take to help prevent incidents of this kind from happening again.<br><br>Even though we believe that there is little risk of fraud or identity theft against the individuals as a result of this incident, we are providing the potentially affected individuals, at our cost, with the identity theft protection services in the attached notification letter, for two years.<br><span style="font-style: italic;">[Evan] If there is "little risk of fraud", then why spend thousands of dollars in notification (because it’s the law, I suppose) and identity theft protection (not required by law)?</span><br><br>Purdue has contracted to provide a two year subscription to TrustedID's IDFreeze.<br><span style="font-style: italic;">[Evan] The cost of </span><a style="font-style: italic;" href="https://www.trustedid.com/registration/identity_theft_protection_products_signup1.php">IDFreeze</a><span style="font-style: italic;"> is $8.25/mo.&nbsp; I am almost certain that Purdue isn't paying this full price and there is a good chance that not all affected persons will enroll, but for demonstration purposes only, $8.25/mo. x 5,000 subscriptions x 24 months = $990,000!</span><br><br>We deeply regret that this incident occurred and take very seriously our obligation to protect the privacy of personal information.<br><br><span style="font-weight: bold;">Commentary:</span><br>Employee and former employee information misuse is a very challenging issue for information security professionals.&nbsp; It's tough to comment because we don't have much detail about what controls are already in place. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/05/12/purdue.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 12 May 2008 14:44:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/information security professionals">information security professionals</category>
      <category domain="http://securityratty.com/tag/purdue pharma">purdue pharma</category>
      <category domain="http://securityratty.com/tag/purdue">purdue</category>
      <category domain="http://securityratty.com/tag/information confidentiality">information confidentiality</category>
      <category domain="http://securityratty.com/tag/employee information misuse">employee information misuse</category>
      <category domain="http://securityratty.com/tag/employee">employee</category>
      <category domain="http://securityratty.com/tag/original disk">original disk</category>
      <source url="http://breachblog.com/2008/05/12/purdue.aspx">Former employee exposes Purdue Pharma personal information</source>
    </item>
    <item>
      <title><![CDATA[Did the Rent-a-Center manager knowingly expose personal information?]]></title>
      <link>http://securityratty.com/article/61e22cbbd808bee3a68e835bb0a92ca3</link>
      <guid>http://securityratty.com/article/61e22cbbd808bee3a68e835bb0a92ca3</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
5/9/08

Organization
Rent-a-Center

formerly RentWay

Contractor/Consultant/Branch
None

Victims
Customers

Number Affected
Unknown

Types of Data...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/rentway.jpg" align="right" height="58" width="200"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>5/9/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www6.rentacenter.com/site/page/pg4285.html">Rent-a-Center</a>*<br><br><font size="1">*formerly RentWay</font><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>"photocopies of Social Security cards and driver's licenses, credit card numbers, home addresses and phone numbers"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"Hundreds of RentWay customer files — including Social Security, driver's license and credit card numbers — were abandoned in a parking lot, leaving consumers at risk for identity fraud."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.heraldtribune.com/article/20080509/BREAKING/32164196/-1/newssitemap">Sarasota Herald-Tribune</a> <br><a href="http://www.bradenton.com/local/story/596353.html">Bradenton Herald</a> <br><a href="http://www.heraldtribune.com/article/20080510/NEWS/805100331/1638/news">Sarasota Herald-Tribune (May 10)</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Anthony Cormier, Sarasota Herald-Tribune<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Hundreds of RentWay customer files — including Social Security, driver's license and credit card numbers — were abandoned in a parking lot, leaving consumers at risk for identity fraud.<br><br>The files were discovered in a plaza off Cortez Road on Friday morning.<br><br>In the files were photocopies of Social Security cards and driver's licenses, credit card numbers, home addresses and phone numbers of people who leased furniture, TVs and appliances from RentWay.<br><br>A Manatee Sheriff's deputy arrived at about 10:30 a.m. and called workers from Rent-A-Center, which acquired RentWay in 2006, to clean up the mess.<br><br>In dress slacks and business shirts, Rent-A-Center employees crawled in a Dumpster on Friday afternoon.<br><br>it was unclear how long the files were in the lot and who may have accessed the sensitive information<br><br>Rather than shredding the documents that contained personal information of clients and taking them to their own Dumpster, the employees left the papers piled in the bottom of the Dots' store Dumpster<br><br>Kimberly Lash, manager of Dots, a women's clothing store next door to the the vacant storefront, said the mess had been out in the corner of the building for nearly a week.<br><br>She said the Rent-A-Center store manager said there were personal documents in the Dumpster.<br><span style="font-style: italic;">[Evan] If I understand this correctly, the Rent-A-Center manager knew that there were personal documents being discarded in the dumpster?!&nbsp; What the *&amp;^# kind of manager would knowingly put his/her customers at risk?&nbsp; I wouldn't hold the Dot's store manager ultimately responsible, but I wonder why she didn't do or say anything when she was told that there was personal information in the dumpster.</span><br><br>"All they did was pick it up and put it in my Dumpster," she said.<br><br>On Friday morning, a transient was seen rifling through the paperwork until he was shooed off by Don McLucas, who found the mess and called police<br><br>"Unbelievable," McLucas said. "Imagine the fraud you could commit with this stuff. And they just dump it like that? Unbelievable."<br><br>"You could open a bank account, apply for a credit card, anything. That information could be worth hundreds of thousands of dollars." - Robert Siciliano, CEO of IDTheftSecurity.com<br><span style="font-style: italic;">[Evan] The bad guys certainly know this.&nbsp; It seems like others either don't care or don't know.</span><br><br>The store manager of the Rent-A-Center store declined to comment. It's unclear what happened to the documents once they were removed from the Dots Dumpster.<br><br>Lt. William Vitaioli said it would not be a criminal violation to dispose of personal information such as Social Security numbers, credit card numbers, driver's license numbers or phone numbers.<br><span style="font-style: italic;">[Evan] Should it be?&nbsp; This is a hot debate.</span><br><br>Florida law requires companies to notify consumers if the security of their personal information has been breached.<br><span style="font-style: italic;">[Evan] Are notification laws working?&nbsp; Another hot debate.</span><br><br><span style="font-weight: bold;">Commentary:</span><br>If I had the time, I would check dumpsters on the way home one of these days.&nbsp; Think I would find anything along my 25 mile ride home? <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/05/12/rentway.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 12 May 2008 11:05:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/store manager">store manager</category>
      <category domain="http://securityratty.com/tag/store">store</category>
      <category domain="http://securityratty.com/tag/store dumpster">store dumpster</category>
      <category domain="http://securityratty.com/tag/rent-a-center store">rent-a-center store</category>
      <category domain="http://securityratty.com/tag/rent-a-center">rent-a-center</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/rent-a-center store manager">rent-a-center store manager</category>
      <category domain="http://securityratty.com/tag/social security cards">social security cards</category>
      <category domain="http://securityratty.com/tag/rent-a-center employees">rent-a-center employees</category>
      <source url="http://breachblog.com/2008/05/12/rentway.aspx">Did the Rent-a-Center manager knowingly expose personal information?</source>
    </item>
    <item>
      <title><![CDATA[Two stolen Saks Incorporated laptops contained sensitive information]]></title>
      <link>http://securityratty.com/article/93d97ba2583b32143ad38008c44b1d57</link>
      <guid>http://securityratty.com/article/93d97ba2583b32143ad38008c44b1d57</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
4/30/08

Organization
Saks Incorporated

Contractor/Consultant/Branch
None

Victims
Customers

Number Affected
Unknown

According to the New Hampshire...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/saks.jpg" align="right" height="75" width="75"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>4/30/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.saksincorporated.com/">Saks Incorporated</a><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown*<br><br><font size="1">*According to the New Hampshire State Attorney General breach notification there were 163 persons affected who reside in the state of New Hampshire<br></font><br><span style="font-weight: bold;">Types of Data:</span><br>Name, address, Saks Fifth Avenue credit card account number, and/or Saks Fifth Avenue/MasterCard co-branded credit card account number.<br><br><span style="font-weight: bold;">Breach Description:</span><br>"In mid-April 2008, Saks learned that four company laptops were stolen.&nbsp; Two of the stolen laptops contained several files that included customer names, addresses, Saks Fifth Avenue credit card account numbers, and/or Saks Fifth Avenue/MasterCard co-branded credit card account numbers."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://doj.nh.gov/consumer/pdf/saks.pdf">New Hampshire State Attorney General breach notification</a><br><br><span style="font-weight: bold;">Report Credit:</span><br>The New Hampshire State Attorney General<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>In mid-April 2008, Saks learned that four company laptops were stolen.&nbsp; Two of the stolen laptops contained several files that included customer names, addresses, Saks Fifth Avenue credit card account numbers, and/or Saks Fifth Avenue/MasterCard co-branded credit card account numbers.<br><br>Based on our investigation, we have confirmed that these files did not include Social Security numbers, the credit cards' expiration dates, pin numbers, codes, or passwords, or any other types of sensitive data.<br><span style="font-style: italic;">[Evan] Thank God for that!</span><br><br>Given the very limited type of personal information on these files and that it was stored on password-protected laptops, we believe there is a very low risk of identity theft or credit card fraud as a result of this event.<br><span style="font-style: italic;">[Evan] I agree with the limited type of information argument, but could care less about password-protected laptops.&nbsp; Password-protected laptops are little more than nothing to stop someone for accessing the information.</span><br style="font-style: italic;"><br>We have no indication that this personal information has been accessed or misused, or even that the laptops are in the hands of someone seeking to misuse the information.<br><br>Nor was this a breach of our network, website, or database (as is typical in many company breaches covered by the news).<br><span style="font-style: italic;">[Evan] I think laptop thefts and losses are more typical that network, website or database breaches.</span><br><br>The company has drafted a written notice of the breach that it will be sending to the affected individuals imminently.<br><br>Saks takes its customers' privacy very seriously, and we have exercised utmost caution and diligence in our response following the discovery of the theft.<br><br>Within hours of learning of the theft, we initiated our own investigation into the incident and notified law enforcement.<br><br>Finally, if you have additional questions related to this situation, you can contact us between the hours of 9:00 a.m. ET through 6:00 p.m. ET on Monday though Saturday through our dedicated toll-free information helpline at 1-888-724-2455.<br><br>We deeply regret any inconvenience or concern that this matter may cause you.<br><br><span style="font-weight: bold;">Commentary:</span><br>The letter sent to the affected individuals is signed by Stephen I. Sadove, Chairman and Chief Executive Office of Saks Incorporated.&nbsp; I respect Mr. Sadove for addressing this situation in person (so to speak).&nbsp; It demonstrates his understanding that information security is a corporate issue for which he is ultimately responsible. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/05/11/saks.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Sun, 11 May 2008 17:28:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/saks">saks</category>
      <category domain="http://securityratty.com/tag/laptops">laptops</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/andor saks">andor saks</category>
      <category domain="http://securityratty.com/tag/company laptops">company laptops</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/breach description">breach description</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/credit card account">credit card account</category>
      <source url="http://breachblog.com/2008/05/11/saks.aspx">Two stolen Saks Incorporated laptops contained sensitive information</source>
    </item>
    <item>
      <title><![CDATA[Personal Las Cruces Public Schools Special Ed information posted online]]></title>
      <link>http://securityratty.com/article/d416168f47cfa9bd568f0552c9159b9e</link>
      <guid>http://securityratty.com/article/d416168f47cfa9bd568f0552c9159b9e</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
5/7/08

Organization
Las Cruces Public Schools (&quot;LCPS

Contractor/Consultant/Branch
None

Victims
Teachers, principals, administrators and other LCPS...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/lcps.jpg" align="right" height="86" width="88"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>5/7/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.lcps.k12.nm.us/">Las Cruces Public Schools ("LCPS")</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Teachers, principals, administrators and other LCPS employees.&nbsp; The breach also affected students enrolled in special education programs.<br><br><span style="font-weight: bold;">Number Affected:</span><br>1,800*<br><br><font size="1">*1,750 teachers, principals, administrators and other LCPS employees who had access to the SEAS system because they work with special education children or programs AND 50 students enrolled in special education programs at various LCPS schools, local charter schools, and home schools</font><br><br><span style="font-weight: bold;">Types of Data:</span><br>"confidential student and staff information, including some personal identifying data"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"LAS CRUCES - The Las Cruces Public Schools has announced that confidential student and staff information, including some personal identifying data, was unintentionally posted on the Internet.&nbsp; Immediately upon learning that the data was posted, the district took steps to remove the data from the Internet site where it was found, said Superintendent Stan Rounds."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://lcps.k12.nm.us/News/News_Releases/080507DataReleasedInadvertantly.doc">LCPS news release (Word document download)</a> <br><a href="http://www.lcps.k12.nm.us/z-temp/Data%20Released%20Speech%20MEDIA.doc">LCPS press conference (Word document download)</a> <br><a href="http://www.lcsun-news.com/ci_9181525">Las Cruces Sun-News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Las Cruces Public Schools<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>LAS CRUCES - The Las Cruces Public Schools has announced that confidential student and staff information, including some personal identifying data, was unintentionally posted on the Internet.&nbsp; Immediately upon learning that the data was posted, the district took steps to remove the data from the Internet site where it was found, said Superintendent Stan Rounds.<br><br>"We began a thorough investigation to determine how this happened and to prevent it from happening in the future.&nbsp; The investigation includes a search of the Internet to determine if the information is located anywhere online and how to remove it."<br><br>Rounds said there is currently no indication that the data has been misused.<br><br>Preliminary information indicates a part-time LCPS computer data analyst unintentionally posted information from a secure LCPS special education computer database, named SEAS (Special Education Automated System), and placed it onto an un-secure website.<br><br>The data in question was contained within two electronic database files that were posted on the Internet between Tuesday, April 29 and Monday, May 5, 2008.<br><br>For the time being, Rounds said he is not disclosing what specific information was posted online to prevent any potential compromise to those affected<br><span style="font-style: italic;">[Evan] The compromise has already taken place.&nbsp; If a bad guy/gal is in possession of the information, he/she probably knows what he/she has without us having to tell him/her.</span><br><br>However, the individuals affected will be notified of what information was released, he said<br><br>Those affected include 1,750 teachers, principals, administrators and other LCPS employees who had access to the SEAS system because they work with special education children or programs.<br><br>Also affected were 50 students enrolled in special education programs at various LCPS schools, local charter schools, and home schools<br><span style="font-style: italic;">[Evan] It especially stinks when children are affected.</span><br><br>Some data for other special education students may have been released as well.<br><br>"We’ve already begun to notify the affected individuals about what specific information is involved and we will assist them in taking appropriate safeguards," Rounds said<br><br>"If we find any of the information on the web, we will immediately take all appropriate steps to have it removed," said Jeff Harris, LCPS director of technology support services.&nbsp; "As of today, we’ve located the data in two Internet sites and removed it.&nbsp; We’re continuing to search for any other locations where it may exist."<br><br>On Monday, May 5, when the Superintendent learned of the potential breach, he directed that each student and staff member affected be provided credit fraud protection for up to one year to ensure their private information was not jeopardized in any way.&nbsp; This will be paid at school district expense.<br><br>Rounds said the experienced part-time employee who unintentionally disclosed the data has been placed on administrative leave and no longer has access to any LCPS computer, data, or server.<br><br>"LCPS goes to great lengths to ensure student and staff confidentiality, but this incident appears to be caused by human error," Rounds said.&nbsp; "This also highlights the need for the district to review its data security and privacy policies to make sure it never happens again."<br><br>Rounds said an ad-hoc committee is being established to immediately review LCPS policies and procedures.&nbsp; This committee will be chaired by Dr. Shaun Cooper, the current Chief Information Officer at New Mexico State University.&nbsp; Cooper is also the former Director of Security and Research Computing at NMSU<br><br><span style="font-weight: bold;">Commentary:</span><br>Human errors will happen as long as we are humans, I suppose.&nbsp; Not that we should just accept defeat and use it as an excuse.&nbsp; There are numerous controls with varying degrees of effectiveness that information security personnel implement to reduce the frequency and impact of human error related breaches.&nbsp; Without knowing more detail, it's hard to say what could have been done better.&nbsp; Was the cause of this breach simple oversight or lack of awareness, poor training, lack of production control (no formal review and approval process for posting information to public sites), etc.&nbsp; I guess I'm not sure.<br><br>I do appreciate Mr. Rounds' response.&nbsp; The response to the breach and notification was swift.&nbsp; I also like the press conference and ad-hoc committee established to review LCPS policy and procedure.&nbsp; I hope that the committee and effort will be ongoing long after this breach is forgotten (by those not personally affected). <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/05/09/lcps.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Fri, 09 May 2008 06:02:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/lcps">lcps</category>
      <category domain="http://securityratty.com/tag/lcps employees">lcps employees</category>
      <category domain="http://securityratty.com/tag/special education students">special education students</category>
      <category domain="http://securityratty.com/tag/lcps press conference">lcps press conference</category>
      <category domain="http://securityratty.com/tag/special education">special education</category>
      <category domain="http://securityratty.com/tag/specific information">specific information</category>
      <category domain="http://securityratty.com/tag/data security">data security</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <source url="http://breachblog.com/2008/05/09/lcps.aspx">Personal Las Cruces Public Schools Special Ed information posted online</source>
    </item>
    <item>
      <title><![CDATA[Confidential information sent to PinPay.net and SoftCard.biz is exposed]]></title>
      <link>http://securityratty.com/article/27cbd575cc28534b9ca368f27ad75124</link>
      <guid>http://securityratty.com/article/27cbd575cc28534b9ca368f27ad75124</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
4/29/08

Organization
ACAP Security Inc

Contractor/Consultant/Branch
PinPay
SoftCard

Victims
Merchants, Agents and customers

Number Affected
Unknown
...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/pinpay.jpg" align="right" height="200" width="178"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>4/29/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.acapsecurity.com">ACAP Security Inc.</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.pinpay.net/index.html">PinPay</a> <br><a href="http://www.softcard.biz/indexaa.html">SoftCard</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Merchants, Agents and customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>Name, mailing address, phone number, email address, date of birth, city of birth, sex, and one or more of the following (chosen from drop-down):<br><br></font><ul><li><font size="2">Passport</font></li><li>Voting ID card</li><li>PAN card</li><li>Driving License card</li><li>Government issued ID card</li><li>Social Security Card</li><li>Military ID card</li><li>Consular ID card</li><li>Postal ID card</li><li>Government Employee ID Card</li><li>Credit Card</li><li>Debit Card<br></li></ul><font size="2"><br><span style="font-weight: bold;">Breach Description:</span><br>ACAP Security and affiliated sites are actively marketing a "secure payment system that allows Internet-based businesses to accept secure PIN-debit card payments and transactions at their online store."&nbsp; The PinPay and SoftCard sign-up pages and account access pages are not adequately secured with encryption, potentially exposing extremely sensitive personal information.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.merchant911.org/blog/index.php/2008/05/05/softcard-vendor-exposing-card-numbers/">Merchant 911 Blog</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Tom Mahoney, the Founder and Director of Merchant 911<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above and my own cursory investigation:<br><br>Back in January, I had short email dialog with a Kip Long, who claimed to be one of the principles of a company called Softcard out of Huntington Beach, CA. They are not to be confused with SoftCard Systems in Athens, GA. As far as I know, SoftCard Systems is a legitimate company with a legitimate product.<br><br>Mr. Long was rather aggressively, but not very successfully, trying to impress me with their product - from what I can make of it, a virtual PIN based card.<br><br>The company uses PinPay - to process transactions and both companies are a part of ACAP Security, Inc.. <br><br>I reviewed their site for possible inclusion in our website’s resource pages, but promptly rejected them.<br><br>their insecure sign-up form - was requesting “Identity Card Numbers” and issue dates. <br><span style="font-style: italic;">[Evan] The sign-up forms at SoftCard.biz and PinPay.net are not secure.&nbsp; Neither are their respected login pages.</span><br><br>“Identity cards” are selectable from a drop down menu and include such ID information as Passport, Driver’s license, SSN, and Credit Card. <br><br>The form also requires a full name and DOB.<br><br>I tried using the HTTPS URL but it appears that they do not have a security certificate tied to their site.<br><br>The fact that Mr. Long used a hotmail address to pitch the company made me wonder too, given that at Merchant911 we try to instill in our members that a free email address from a customer is a fraud alert.<br><br>If a company official can’t use his company’s domain for email, I’m not going to talk to him.<br><br>I called their attention to the insecure web form in January. They still have the form up there, happily collecting this information with an insecure form.<br><span style="font-style: italic;">[Evan] I also sent emails and heard nothing in return.</span><br><br>I have to wonder how much information has already been sniffed or otherwise compromised. You probably don’t want to fill out this form.<br><span style="font-style: italic;">[Evan] My advice would be to <span style="font-weight: bold;">NOT </span>fill out the form and <span style="font-weight: bold;">NOT </span>conduct business with a company that has not demonstrated a willingness to secure your information.</span><br><br><span style="font-weight: bold;">Commentary:</span><br>Tom informed me about this vulnerability (and potentially a breach for anyone that signed-up/in) a couple of weeks ago.&nbsp; I've been a little busy lately, but was finally able to check it out.&nbsp; Let me recap what I found.<br><br>First, let's go to <a href="http://www.softcard.biz.%C2%A0">www.softcard.biz.</a> This is the site that Tom originally pointed out to me.<br><br><img src="http://images.quickblogcast.com/95781-88451/softcardhome.jpg" border="0" width="485"><br><br>The flash home page forwards visitors to a static index (indexaa.html) page.&nbsp; The first paragraph on the page informs visitors about PinPay.<br><br>"The PINPAY SoftCard is a wise way to carry and transfer money. It gives you the ability to purchase products at participating stores throughout the world (as well as at online shopping malls), with the security of a PIN that travels the internet via private encrypted tunnels. It also allows you the ability to load money to your card, pay bills, transfer money to merchants, transfer money between cards, and withdraw cash from your card at the store."<br><br><img src="http://images.quickblogcast.com/95781-88451/registerforfree.jpg" border="0" width="574"><br><br>See where the page says, "Register for your FREE card HERE!!"?&nbsp; This is a link to the sign-up page that Tom was referring to.<br><br><img src="http://images.quickblogcast.com/95781-88451/signupurl.jpg" border="0" width="304"><br><br>No "https" in the URL.&nbsp; Tom was right on that.&nbsp; The sign-up form asks for a personal information ranging from name and address to identity card information (even information for a "Second Identity Card").<br><br><img src="http://images.quickblogcast.com/95781-88451/form.jpg" border="0" width="431"><br><br>The "Select Identity Card" drop down menu displays the choices for the prospective customer, including Passport, Voting ID card, PAN card, Drivers License card, Government issued ID card, Social Security card, Military ID card, Consular ID card, Postal ID card, Government Employee ID Card, Credit Card and Debit Card<br><br><img src="http://images.quickblogcast.com/95781-88451/dropdown.jpg" border="0" width="459"><br><br>SoftCard (or PinPay or ACAP Security) are asking for some very sensitive personal information!&nbsp; First, this is quite a bit more information than they need to approve a person for a "PINPAY SoftCard".&nbsp; Second, no encryption?!&nbsp; Third, who is ACAP/SoftCard/PinPay and what will they do to secure my information once they have it supposing it wasn't intercepted on the way to them?<br><br>Let's dig a little (public) information about ACAP Security.&nbsp; According to <a href="http://www.entrepreneur.com/tradejournals/article/120829630.html">Entreprenuer.com</a>, ACAP launched "Personal Private Network" (ppn) technology, commercially available under the trade name ppnPRO, which is described as a "highly secure, and highly private" personal private network.&nbsp; ppnPRO uses "Government approved AES encryption, with strong personalized 256-bit encryption keys, and encrypting all information- network addresses, applications and ports, as well as the confidential data content".&nbsp; Sounds impressive, but it also sounds like the company should know a thing or two about securing web site transactions with encryption.&nbsp; <br><br>I want to discuss the risk of sending confidential private information over a public network such as the internet without encryption, in particular.&nbsp; This is not a new topic, but I will take some time to demonstrate the risk.<br><br>In order for my information to be compromised, someone (or something) will need to capture the traffic.&nbsp; In order for someone to capture my traffic, they will need to tap into the communication somewhere between me (my computer) and the destination (the web server).&nbsp; My information doesn't travel directly from my computer to the server.&nbsp; There are intermediaries (routers, switches, firewalls, etc.) that have to get (or forward) my information from my computer to the server.<br><br><img src="http://images.quickblogcast.com/95781-88451/trace.jpg" border="0" width="575"><br><br>As you can see depicted in the graphic above, there are at least 16 routers (or hops) between this example source and <a href="http://www.softcard.biz.%C2%A0">www.softcard.biz.&nbsp;</a> The final few hops are not reported due to filtering.&nbsp; So where could my traffic be captured?&nbsp; At the very least:<br><br></font><ul><li><font size="2">Between my computer and my router (or firewall)</font></li><li>Between my firewall and the ISP hand-off</li><li>Between all the traversed devices within my ISP's network</li><li>Between all the traversed devices through the internet</li><li>Between all the traversed devices within the destination ISP's network</li><li>Between all the traversed devices within the destination organization's network and the server itself.<br></li></ul><font size="2">Anyone in the communication path can use a simple protocol analyzer like <a href="http://www.wireshark.org">Wireshark</a> and capture the sensitive information:<br><br>txtfname=Billy&amp;txtmname=J&amp;txtlname=Madison&amp;txtaddress=123+Main+Street&amp;txtcity=Anywhere&amp;<br>txtstate=MA&amp;txtzip=87451&amp;txtcountry=United+States&amp;mob_phone=NONE&amp;txtphone=18006218200&amp;<br>txtemail=billymadison@honky.com&amp;txtdob=04%2F20%2F1988&amp;txtbirthcity=Boston&amp;<br>txtbirthcountry=United+States&amp;txtgender=M&amp;identity1=Social+Security+Card&amp;txtcardno1=123-45-6789&amp;<br>txtissuedate1=04%2F20%2F1988&amp;identity2=Driving+License+card&amp;txtcardno2=M-1234567890&amp;<br>txtissuedate2=04%2F20%2F2006&amp;submit=Accept+Card+Agreement-Submit<br><br>This is a very simplistic demonstration about why it is important to encrypt sensitive information.&nbsp; If the communication had been encrypted, none of the data would have been visible without access to the private key.<br><br>We could go deeper into the server application and SQL, but I think that this is enough.<br><br>A Quote from the ACAP Security CEO:<br></font>“The right of privacy is a fundamental
          and very important right of American society. A right our Nation’s
          founders fought the American Revolution to obtain and a right many
          brave American soldiers have fought and continue to fight and die
          to preserve. As this Nation continues to advance into cyberspace, we
          have
          expanded the right of privacy to include the right to electronic privacy.
          The elements of cyber-crime and cyber-vulnerabilities have begun to
          seriously erode and destroy this important right of electronic privacy.”<br><font size="2"><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/05/08/pinpay.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Thu, 08 May 2008 09:26:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/drivers license card">drivers license card</category>
      <category domain="http://securityratty.com/tag/license card">license card</category>
      <category domain="http://securityratty.com/tag/card">card</category>
      <category domain="http://securityratty.com/tag/free card">free card</category>
      <category domain="http://securityratty.com/tag/social security card">social security card</category>
      <category domain="http://securityratty.com/tag/sensitive information">sensitive information</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/encrypt sensitive information">encrypt sensitive information</category>
      <source url="http://breachblog.com/2008/05/08/pinpay.aspx">Confidential information sent to PinPay.net and SoftCard.biz is exposed</source>
    </item>
    <item>
      <title><![CDATA[Personal information from two Colorado mortgage companies found in dumpsters]]></title>
      <link>http://securityratty.com/article/7ae56d34b365648af4041ccd173db81f</link>
      <guid>http://securityratty.com/article/7ae56d34b365648af4041ccd173db81f</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
4/28/08

Organization
Cove Creek Mortgage
Front Range Mortgage, LLC

Contractor/Consultant/Branch
None

Victims
Customers

Number Affected
Unknown

Types...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/covecreek.jpg" align="right" height="82" width="167"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>4/28/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.covecreekmortgage.com/">Cove Creek Mortgage</a> <br><a href="http://www.frontrangemortgage.com/">Front Range Mortgage, LLC</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>Mortgage files, tax returns, pay stubs, Social Security numbers, and other personal information<br><br><span style="font-weight: bold;">Breach Description:</span><br>"ENGLEWOOD, Colo. -- The Arapahoe County District Attorney's Office is advising anyone who has used Cove Creek Mortgage to watch out for identity theft after hundreds of mortgage files were dumped in a public trash bin over the weekend."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.thedenverchannel.com/news/16038972/detail.html">Denver Channel 7 News</a> <br><a href="http://www.thedenverchannel.com/news/16064711/detail.html">Denver Channel 7 News (update)</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Denver Channel 7 News<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>ENGLEWOOD, Colo. -- The Arapahoe County District Attorney's Office is advising anyone who has used Cove Creek Mortgage to watch out for identity theft after hundreds of mortgage files were dumped in a public trash bin over the weekend.<br><span style="font-style: italic;">[Evan] Cove Creek Mortgage joins the ranks of other mortgage companies reported for similar breaches on The Breach Blog.&nbsp; The others are </span><a style="font-style: italic;" href="http://breachblog.com/2008/03/19/affordable.aspx">Affordable Realty</a><span style="font-style: italic;"> and </span><a style="font-style: italic;" href="http://breachblog.com/2008/02/29/unionmortgage.aspx">Union Mortgage Services of Cleveland, Inc.</a><span style="font-style: italic;">. </span><br><br>Cove Creek's owner had abandoned his Englewood office in January, and property managers had not been able to find him<br><i>[Evan] What kind of businessman just abandons an office full of confidential files and equipment?</i><br><br>On Saturday, the property manager had a crew clean out his office and throw all items from the office -- including complete mortgage files -- into two Dumpsters.<br><i>[Evan] Maybe the property manager should pay a little closer attention to the things they throw in the dumpster.&nbsp; Having said this, the property manager is not really at fault.</i><br><br>David Peters who works in the same complex found the files Monday morning.<br><br>"I was taking some other trash out to the garbage can and opened the lid and on there was a couple of laptops,"<br><br>"Directly underneath them were files with people's names on it and I was like, 'Well, this is not right.'"<br><br>"There were tax returns, pay stubs, everything in there," he said. "And as I looked at the different files I realized that it was mortgage files, which was kind of scary, because who do you disclose the most information to or all of your information? That is when you are getting a mortgage loan."<br><i>[Evan] According to the news report, Mr. Peters contacted authorities.&nbsp; This could have easily been much worse for victims.</i><br><br>The Dumpsters were not secured and located at 88 Inverness Drive East, Bldg. F.<br><br>Sheriff's investigators finally found the owner of Cove Creek and talked him into retrieving the files, many of which had private information, including Social Security numbers and credit history.<br><span style="font-style: italic;">[Evan] Mr. owner guy, will you please come get your stuff and the personal information that was entrusted to you?&nbsp; According to </span><a style="font-style: italic;" href="http://www.zoominfo.com/Search/PersonDetail.aspx?PersonID=41991084">zoominfo</a><span style="font-style: italic;"> a guy named Charlie Cartwright is/was the president of Cove Creek Mortgage.&nbsp; I have no idea if this is the same guy that is referred to in the news article.</span><br><br>The district aAttorney's office got a tip about numerous mortgage files and two laptop computers in a Dumpster behind offices formerly used by Cove Creek Mortgage and Front Range Mortgage.<br><i>[Evan] Now Front Range Mortgage joins the ranks.&nbsp; Front Range Mortgage offers <a href="http://www.frontrangemortgage.com/credit_consultants.html">credit repair services</a> too! Do you suppose they could have repaired the damage that could have been done?</i><br><br>"With a name, Social Security number and bank account number, they can clean you out before you even know," said Arapahoe County District Attorney Carol Chambers.<br><br>The files and computers contained sensitive information on many former customers of Front Range Mortgage, including names and addresses, Social Security numbers and bank, credit card and investment account information.<br><br>While there are civil laws against dumping such documentation, Chambers said it is not against the law.<br><i>[Evan] It's too bad that we have to write and enforce laws to protect us from idiots.</i><br><br>"I think it is a matter of legislation not catching up with the realities of identity theft," said Chambers. "And absolutely, we think recklessly disposing or negligently disposing of this kind of information should maybe carry a criminal penalty, just to get people's attention that you can't just leave this information or leave it out in a Dumpster."<br><br>"The district attorney recommends that any former customers of Front Range or Cove Creek should place a fraud alert on their credit reports and monitor any bank, credit card or investment accounts that might have been included on a mortgage application with that firm."<br><br>For further information, assistance or questions, call the District Attorney's Fraud Assistance Line at 720-874-8547.<br><br><b>Commentary:</b><br>What is with these mortgage companies?&nbsp; The 90's and early 2000's was a wild ride for mortgage brokers, real estate agents, and investors.&nbsp; The money attracted people from all walks of life and a lot of poor decisions were made.&nbsp; Now that the bubble has burst, we start to see the true colors of some of these "professionals".<br><br>I don't know much if anything about the owners of these companies, but I do know that securing personal information poorly is bad business. <br><br><b>Past Breaches:</b><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/05/07/covecreek.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Wed, 07 May 2008 18:20:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mortgage files">mortgage files</category>
      <category domain="http://securityratty.com/tag/numerous mortgage files">numerous mortgage files</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/complete mortgage files">complete mortgage files</category>
      <category domain="http://securityratty.com/tag/personal information poorly">personal information poorly</category>
      <category domain="http://securityratty.com/tag/files">files</category>
      <category domain="http://securityratty.com/tag/cove creek mortgage">cove creek mortgage</category>
      <category domain="http://securityratty.com/tag/cove creek">cove creek</category>
      <source url="http://breachblog.com/2008/05/07/covecreek.aspx">Personal information from two Colorado mortgage companies found in dumpsters</source>
    </item>
  </channel>
</rss>
