<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: chipotle]]></title>
    <link>http://securityratty.com/tag/chipotle</link>
    <description></description>
    <pubDate>Sat, 26 Apr 2008 18:39:08 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Chipotle Mexican Grill employee information on USi stolen laptop]]></title>
      <link>http://securityratty.com/article/d1a2ed55b9f05cd298be720ce8bff786</link>
      <guid>http://securityratty.com/article/d1a2ed55b9f05cd298be720ce8bff786</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
4/15/08 (this incident is also the cause of Stolen USinternetworking laptop affects hundreds of SPX employees AND Stolen USinternetworking laptop also...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/chipotle.jpg" align="right" height="112" width="119"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>4/15/08 (this incident is also the cause of <a href="http://breachblog.com/2008/04/22/spx.aspx">Stolen USinternetworking laptop affects hundreds of SPX employees</a> AND <a href="http://breachblog.com/2008/04/24/xl.aspx">Stolen USinternetworking laptop also affects XL employees</a>)<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.chipotle.com/">Chipotle Mexican Grill</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.usi.com/">USinternetworking ("USi")</a>* <br><br><font size="1">*From the USinternetworking "About Us" page:<br>Founded in 1998, USinternetworking, Inc. (USi), an AT&amp;T company, is the most experienced Application Service Provider (ASP). We use a highly automated, efficient, systematic approach to deliver managed hosting, application management, remote management, professional services, SaaS enablement, and eBusiness development and hosting to more than 150 enterprise-level organizations in over 30 countries.</font><br><br><span style="font-weight: bold;">Victims:</span><br>Current and former Chipotle employees<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>"name, address, Social Security number, and payroll information"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"USi, a service company that was doing information technology work for Chipotle to support human resources and payroll, has notified Chipotle that on or about March 23, 2008, a USi employee residing in Columbus, Ohio was the victim of a burglary, during which a laptop computer, containing Chipotle information, was stolen."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://doj.nh.gov/consumer/pdf/chipotle.pdf">New Hampshire State Attorney General breach notification part 1</a> <br><a href="http://doj.nh.gov/consumer/pdf/chipotle2.pdf">New Hampshire State Attorney General breach notification part 2</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>The New Hampshire State Attorney General<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>USi, a service company that was doing information technology work for Chipotle to support human resources and payroll, has notified Chipotle that on or about March 23, 2008, a USi employee residing in Columbus, Ohio was the victim of a burglary, during which a laptop computer, containing Chipotle information, was stolen.<br><span style="font-style: italic;">[Evan] USi was storing confidential information obtained from at least three different companies on a single, poorly protected laptop computer.&nbsp; Sad, but true.</span><br><br>Unfortunately, USi informs us that some information, including name, address, Social Security number, and payroll information for Chipotle employees and former employees was contained on the stolen laptop.<br><span style="font-style: italic;">[Evan] "Unfortunately"?&nbsp; Is the cause of this breach attributed more to fortune than it is to poor information security management?&nbsp; I don't fortune has all that much to do with it.</span><br><br>USi has reported the theft to Ohio law enforcement authorities and believes the theft was a random act.<br><br>At this time, we have no evidence that this information has been misused, and USi indicates that the laptop was password protected.<br><span style="font-style: italic;">[Evan] This statement (or very similar) appears in each of the three breach notifications that I have read about this incident.&nbsp; You could almost copy and paste it, eh?&nbsp; It is probably too early for any evidence of misuse (a smart fraudster would wait until the identity theft protection runs out, or would sell the information to someone else).&nbsp; Password protection (likely operating system) is little more than no protection.&nbsp; An operating system password would not suffice as adequate protection for most information security professionals.</span><br><br>we want to make you aware of the incident and the steps that have been taken to prevent a reoccurence<br><span style="font-style: italic;">[Evan] USi also made this (or similar) statement in each of the breach notifications, but there were never any "steps" listed anywhere</span><br><br>access to Continuous Credit Monitoring and Enhanced Identity Theft Restoration at no cost to you for 2 years.<br><br>If you have questions or feel you may have an identity theft issue, please call ID TheftSmart member services at 1-800-588-9839 between 8:00 a.m. and 5:00 p.m. (Central Time), Monday through Friday<br><br>Chipotle sincerely regrets this unfortunate incident and is currently taking steps to ensure that its privacy policies are strictly followed to avoid similar issues.<br><span style="font-style: italic;">[Evan] Chipotle, its employees, its investors, and its customers would all benefit from information security improvement, including (but certainly not limited to) vendor/contractor information security policies and mandatory standards, enforcement of the policies and standards, and periodic auditing of vendor compliance with the policies and standards.&nbsp; Information security is necessary at all phases of vendor relationships (need definition, negotiation, contractual language, etc.) just as it is at all phases of software development.</span><br><br><span style="font-weight: bold;">Commentary:</span><br>Well, I wonder if this is the last company affected by this single stolen USi laptop. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Chipotle:<br>Unknown<br>USinternetworking:<br>April, 2008 - <a href="http://breachblog.com/2008/04/24/xl.aspx">Stolen USinternetworking laptop also affects XL employees</a> <br>April, 2008 - <a href="http://breachblog.com/2008/04/22/spx.aspx">Stolen USinternetworking laptop affects hundreds of SPX employees</a><br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/04/26/chipotle.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Sat, 26 Apr 2008 18:39:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/usi">usi</category>
      <category domain="http://securityratty.com/tag/information security improvement">information security improvement</category>
      <category domain="http://securityratty.com/tag/chipotle">chipotle</category>
      <category domain="http://securityratty.com/tag/information security policies">information security policies</category>
      <category domain="http://securityratty.com/tag/chipotle information">chipotle information</category>
      <category domain="http://securityratty.com/tag/evan">evan</category>
      <source url="http://breachblog.com/2008/04/26/chipotle.aspx">Chipotle Mexican Grill employee information on USi stolen laptop</source>
    </item>
  </channel>
</rss>
