<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: aib]]></title>
    <link>http://securityratty.com/tag/aib</link>
    <description></description>
    <pubDate>Wed, 28 Nov 2007 14:08:26 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[AIB confirms payment receipts mix-up]]></title>
      <link>http://securityratty.com/article/20b04978d19103432c6503fb7cdb0888</link>
      <guid>http://securityratty.com/article/20b04978d19103432c6503fb7cdb0888</guid>
      <description><![CDATA[AIB confirmed Thursday evening that a computer error caused 15,000 payment advice slips to be sent to the wrong...]]></description>
      <content:encoded><![CDATA[AIB confirmed Thursday evening that a computer error caused 15,000 payment advice slips to be sent to the wrong addresses.]]></content:encoded>
      <pubDate>Fri, 28 Dec 2007 10:15:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/payment advice slips">payment advice slips</category>
      <category domain="http://securityratty.com/tag/aib">aib</category>
      <category domain="http://securityratty.com/tag/wrong addresses">wrong addresses</category>
      <category domain="http://securityratty.com/tag/computer error">computer error</category>
      <category domain="http://securityratty.com/tag/thursday">thursday</category>
      <source url="http://www.enn.ie/article/10123485.html">AIB confirms payment receipts mix-up</source>
    </item>
    <item>
      <title><![CDATA[AIB technical problem discloses details of bank transfers]]></title>
      <link>http://securityratty.com/article/e9e4e49686bbca7d3d82fcf2967adea5</link>
      <guid>http://securityratty.com/article/e9e4e49686bbca7d3d82fcf2967adea5</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
11/21/07

Organization
Allied Irish Bank (AI

Contractor/Consultant/Branch
None

Victims
Certain AIB customers who made or received international...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/aib.jpg" align="right" height="85" width="61"><span style="font-weight: bold;">Date Reported: </span><br>11/21/07<br><br><span style="font-weight: bold;">Organization: </span><br>Allied Irish Bank (AI<img src="http://breachblog.com/emoticons/cool.png" border="0" /><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Certain AIB customers who made or received international payments between November 13th and 15th, 2007.&nbsp; Some customers of other banks involved in the transactions may also be affected.<br><br><span style="font-weight: bold;">Number Affected:</span><br>11,000*<br><br><font size="1">*AIB customers, unknown number of victims that are customers of other banks</font><br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, addresses and "private bank account details".<br><br><span style="font-weight: bold;">Breach Description:</span><br>The announcement from AIB sums this breach up well; "A technical problem occurred in the issuing of these advice notices to some AIB customers that made international payments between the 13th and 15th November 2007. This affected 15,000 payment advices, which were sent in error to the wrong customers."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.ireland.com/newspaper/frontpage/2007/1123/1195682121693.html?via=me" target="_blank"> The Irish Times Story</a><br><a href="http://www.computerweekly.com/Articles/2007/11/23/228268/allied-irish-sends-personal-details-to-the-wrong-people.htm" target="_blank"> Computer Weekly Story</a><br><a href="http://www.rte.ie/business/2007/1122/aib.html" target="_blank"> RTE Business Story</a><br><br><span style="font-weight: bold;">Report Credit:</span><br>The Irish Times<br><br><span style="font-weight: bold;">Response:</span><br>From the sources cited above:<br><br>A significant error at AIB bank earlier this month led it to send 15,000 notifications to its customers containing the private bank account details of other individuals. A total of 11,000 AIB customers are affected by the move, writes John Downes<br><br>Last night, it also emerged that some of the bank account details sent to AIB customers in recent days relate not just to AIB accounts, but also reveal the names and bank account details of customers with other banks.<br><br>It is understood that as many as 7,500 of the notices contained the names, addresses and full bank account numbers of AIB customers.This means these details, contained in notices relating to "inward" payments, are now in the possession of other customers of the bank.<br><br>Most of the remaining "outward" payment notices included the name of a bank account holder, usually with a bank other than AIB, and their account numbers, but not their address.<br><br>A bank spokesman said the information in question was no more or less than would be contained in a company invoice or cheque<br><span style="font-style: italic;">[Comfyllama] Which wouldn't be a big deal if this information were meant to be public, but it WASN'T.</span><br><br>However the error, which AIB said was the result of a "technical problem" in the issuing of international payment advice notices, has been labelled a "serious breach" by a spokesman for the Office of the Data Protection Commissioner.<br><span style="font-style: italic;">[Comfyllama] Sounds like someone made a change to one or more internal systems, likely without thorough testing and/or validation.</span><br><br>Customers of the bank who either received or transferred an international payment between November 13th and 15th are affected by the error.<br><br>Those who received the notices were wrongly provided with details relating to someone else's transaction. As a result, they were incorrectly told the transaction related to their account.<br><span style="font-style: italic;">[Comfyllama] Can you imagine receiving a notice that X number of Euro (EUR) were transferred from your account, and you had nothing to do with it.&nbsp; My heart would just about burst out of my chest!</span><br><br>The bank stressed that no customer accounts have been incorrectly credited or debited as a result of the error. A company spokesman added that it had "nothing whatsoever" to do with computer "hackers" or other unauthorised parties attempting to access its system.<br><br>AIB has informed the Office of Data Protection Commissioner which is awaiting an AIB report on the matter in the coming days. The company said it would allow affected customers to change their bank account details should they so wish.<br><br>"AIB regrets that this occurred and is currently writing to each customer involved to apologise, to explain how this occurred and to reassure them that this was an isolated error," the bank said.<br><br>One of the incorrect notices, seen by The Irish Times , wrongly informed the customer that a payment of €5,000 had been made from their business account to an account with the Bank of China.<br><br><span style="font-weight: bold;">Commentary:</span><br>Errors will always be a part of our daily lives, but at the same time we should do everything within reason to prevent them.&nbsp; In IT, this is one of the primary reasons for proper change control processes.&nbsp; As a part of most good change control, testing and validation are completed before the change is successful.&nbsp; If testing and/or validation fail, a roll-back is initiated.<br><br>I'm not sure what AIB's change control processes or procedures are, but in this case they appear to have failed.&nbsp; I am also not sure how sensitive the data involved actually is, so determining the risk to victims is a little sketchy.&nbsp; Many IT folks aren't particularly fond of change control (and documentation in general), but this may be a good case to demonstrate its importance. <br><br>Now that I think a little more, these changes should have been thoroughly tested on a test platform prior to production implementation also.<br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2007/11/28/aib.aspx" type="text/javascript" charset="utf-8"></script>
<br>
<br>
<script type="text/javascript"><!--
google_ad_client = "pub-4721162729073131";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_ad_channel = "";
//-->
</script>
<script type="text/javascript">
</script>]]></content:encoded>
      <pubDate>Wed, 28 Nov 2007 14:08:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bank">bank</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/bank account details">bank account details</category>
      <category domain="http://securityratty.com/tag/aib bank">aib bank</category>
      <category domain="http://securityratty.com/tag/bank account">bank account</category>
      <category domain="http://securityratty.com/tag/aib">aib</category>
      <category domain="http://securityratty.com/tag/details">details</category>
      <category domain="http://securityratty.com/tag/wrong customers">wrong customers</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <source url="http://breachblog.com/2007/11/28/aib.aspx">AIB technical problem discloses details of bank transfers</source>
    </item>
  </channel>
</rss>
