<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: confidential]]></title>
    <link>http://securityratty.com/tag/confidential</link>
    <description></description>
    <pubDate>Wed, 09 Jul 2008 19:37:10 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Backup tape is stolen from Bristol-Myers Squibb]]></title>
      <link>http://securityratty.com/article/911478f22f756b8e8513c59d7f720d18</link>
      <guid>http://securityratty.com/article/911478f22f756b8e8513c59d7f720d18</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/17/08

Organization
Bristol-Myers Squibb Co. (&quot;BMS

Contractor/Consultant/Branch
Unknown

Victims
Current and former employees and some dependants
...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/bms.jpg" width="198" align="right" height="160"><font size="2"><b>Date Reported: </b><br>7/17/08<br><br><b>Organization: </b><br><a href="http://www.bms.com/landing/data/index.html">Bristol-Myers Squibb Co. ("BMS")</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>Unknown<br><br><span style="font-weight: bold;">Victims:</span><br>Current and former employees and some dependants<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown*<br><br><font size="1">*Bristol-Myers Squibb had "about 42,000 employees as of Dec. 31, the last date for which work force figures were available in regulatory filings.", Source: <a href="http://money.cnn.com/news/newsfeeds/articles/djf500/200807171514DOWJONESDJONLINE000844_FORTUNE5.htm">CNN Money</a></font> <br><br><span style="font-weight: bold;">Types of Data:</span><br>"name, address, date of birth, Social Security number, marital status, gender, salary, hire date, termination date, retirement date, and, in some instances bank account information"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"On June 4, 2008, Bristol-Myers Squibb Company ("BMS") learned that a back-up data tape containing BMS-related data was stolen while it was being transported for storage.&nbsp; Through subsequent forensic work, it was determined that the data tape included personal information of current and former BMS employees"<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.pharmalot.com/wp-content/uploads/2008/07/bms_letter.pdf">Pharmalot (copy of notification letter)</a> <br><a href="http://www.pharmalot.com/2008/07/bristol-myers-security-breach-hits-untold-thousands/">Pharmalot</a> <br><a href="http://money.cnn.com/news/newsfeeds/articles/djf500/200807171514DOWJONESDJONLINE000844_FORTUNE5.htm">CNNMoney</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Ed Silverman, Pharmalot<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>The drugmaker sent letters over the past week saying a data tape containing reams of personal information was stolen several weeks ago<br><br>On June 4, 2008, Bristol-Myers Squibb Company ("BMS") learned that a back-up data tape containing BMS-related data was stolen while it was being transported for storage. <br><span style="font-style: italic;">[Evan] This statement prompted me to list the contractor as "unknown" instead of "none".&nbsp; I presume that the data tape was being transported by a third-party vendor when it was stolen.&nbsp; I am looking for more information on this.</span><br><br>Through subsequent forensic work, it was determined that the data tape included personal information of current and former BMS employees, such as name, address, date of birth, Social Security number, marital status, gender, salary, hire date, termination date, retirement date, and, in some instances, bank account information.<br><span style="font-style: italic;">[Evan] Ugh, this looks like very sensitive HR and benefits data.</span><br><br>The names, addresses, and Social Security numbers of some employee dependents also were included on the tape.<br><br>an untold number of current and former employees - and their dependents - could be affected<br><br>BMS has initiated an investigation of this incident.<br><br>To date, BMS has no reason to believe that any of your personal information has been inappropriately accessed from the data tape by an unauthorized party, or that any identity theft, fraud or misuse of your personal information has occurred.<br><span style="font-style: italic;">[Evan] I agree with most of this statement except for the "misuse" part.&nbsp; There may be no evidence of misuse post stolen tape, but there may be an argument for misuse by BMS themselves.&nbsp; BMS is the data custodian in this scenario, not the data owner.&nbsp; If a data custodian does not care for the owner's information in a manner that is expected or communicated, does it constitute misuse?</span><br><br>In addition, there is no evidence that the data tape or the information contained on it was the target of the theft.<br><span style="font-style: italic;">[Evan] I am interested in knowing more about who was transporting the tape and whether or not other items were taken.</span><br><br>As a precaution, to help you detect any possible misuse of your data, BMS has arranged for you to enroll in credit monitoring for one full year, at no cost to you.<br><span style="font-style: italic;">[Evan] There is that "misuse" mention again.&nbsp; One year of free credit monitoring does nothing to protect a victim against fraud that occurs after one year, supposing the victim does not renew at his/her own expense.&nbsp; I wonder how many people renew on average.</span><br><br>If you have any questions, you may call the dedicated Privacy Help Line at 1-877-214-0689.&nbsp; Our representatives will be available to assist you Monday through Friday, between 8 a.m. and 5 p.m. ET.<br><br>the drugmaker is issuing this statement: "Bristol-Myers Squibb regrets that this incident occurred and is committed to providing appropriate assistance for affected individuals who had their personal information on the stolen data tape. We are committed to protecting the privacy and security of employee and dependent information. Maintaining the trust and confidence of our employees is paramount to Bristol-Myers Squibb."<br><br>Protecting the privacy and security of your information is extremely important to us.<br><br>In this regard, BMS wishes to reiterate that it does not have any evidence indicating that your personal information has been misused.<br><span style="font-style: italic;">[Evan] Another "misuse" mention.</span><br><br>the company is taking appropriate remedial steps, including enhancing security protocols regarding the handling of personal information and our back-up data tapes.<br><span style="font-style: italic;">[Evan] Like what? Encryption maybe?</span><br><br>On behalf of BMS, I apologize for any inconvenience or concern that this matter may cause for you.<br><br><span style="font-weight: bold;">Commentary:</span><br>I couldn't find any mention about encryption or whether or not police were called.&nbsp; You would think that a large, well-repected company like Bristol-Myers Squibb encrypts confidential data on tape, right? <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/18/bms.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 07:26:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tape">tape</category>
      <category domain="http://securityratty.com/tag/back-up data tape">back-up data tape</category>
      <category domain="http://securityratty.com/tag/data tape">data tape</category>
      <category domain="http://securityratty.com/tag/owner">owner</category>
      <category domain="http://securityratty.com/tag/data owner">data owner</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/bristol-myers squibb">bristol-myers squibb</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <source url="http://breachblog.com/2008/07/18/bms.aspx">Backup tape is stolen from Bristol-Myers Squibb</source>
    </item>
    <item>
      <title><![CDATA[Mailing error at the University of Maryland exposes student information]]></title>
      <link>http://securityratty.com/article/a51262d40f98a67474833c65ff29621e</link>
      <guid>http://securityratty.com/article/a51262d40f98a67474833c65ff29621e</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/17/08

Organization
University of Maryland

Contractor/Consultant/Branch
Department of Transportation Services

Victims
All students registered for...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/umd.jpg" width="88" align="right" height="83"><font size="2"><b>Date Reported: </b><br>7/17/08<br><br><b>Organization: </b><br><a href="http://www.umd.edu/">University of Maryland</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.transportation.umd.edu/index.html">Department of Transportation Services</a> <br><br><span style="font-weight: bold;">Victims:</span><br>All students registered for Fall 2008 classes<br><br><span style="font-weight: bold;">Number Affected:</span><br>23,727<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, addresses, and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>On July 1st, 2008, the University of Maryland Department of Transportation Services mailed an </font><font size="2">on-campus parking </font><font size="2">brochure to all students </font><font size="2">registered for Fall 2008 classes</font><font size="2"> as of June 15, 2008.&nbsp; Recipient Social Security numbers were inadvertently exposed on the mailing labels.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.transportation.umd.edu/parkingmailer/">University of Maryland</a> <br><a href="http://www.wjla.com/news/stories/0708/536794.html">ABC Channel 7 News</a> <br><a href="http://www.wtop.com/?sid=1442585&amp;nid=25">WTOP FM 103.5 News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>University of Maryland<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>On July 1st, 2008, the University of Maryland’s Department of Transportation Services sent all students registered at the time, by U.S. mail, a brochure with on-campus parking information.<br><br>On July 8, 2008, the University discovered that the labels on that mailing included the addressees’ Social Security numbers.<br><span style="font-style: italic;">[Evan] Sheesh, a fraudster doesn't even have to tamper with the mail if the Social Security number is on the label.</span><br><br>The error was discovered on the morning of July 8 when calls were made to the University.<br><br>This parking mailer was sent to all individuals registered for Fall 2008 classes at the University of Maryland as of June 15, 2008.<br><br>The mailing list numbered 23,727 individuals.<br><br>In our annual effort to provide parking and transportation information to the University community, the names and addresses of all registered students was requested internally at the Department of Transportation Services for the purpose of creating mailing labels for a brochure.<br><br>This information was generated by a computer query and included names, addresses and what was believed to be University identification numbers (UIDs).<br><span style="font-style: italic;">[Evan] When writing and executing database queries, isn't it a good idea to check the results and see if the information displayed is the information you were looking for?&nbsp; I wonder if UIDs are also nine digits long like Social Security numbers are.</span><br><br>Our normal process is to remove the University ID numbers prior to mailing.<br><span style="font-style: italic;">[Evan] Is it safe to assume that "normal process" was not followed in this instance?&nbsp; If so, then why not?&nbsp; There is no mention in the school's response.</span><br><br>It was not apparent to departmental staff that these numbers not only still existed within the file, but were Social Security numbers, and not University ID numbers.<br><span style="font-style: italic;">[Evan] Not apparent?&nbsp; They were on the labels!</span><br><br>The numbers were not identified as Social Security numbers and did not show the normal spacing between digits.<br><span style="font-style: italic;">[Evan] So it would be xxxxxxxxx instead of xxx-xx-xxxx.&nbsp; What percentage of people would recognize the first set of nine digits as a SSN?</span><br><br>This mailer was sent using third class, bulk mail delivery and may not have been delivered to you yet.<br><br>Currently, there is no evidence that anyone's Social Security number has been misused.<br><br>The University apologizes and deeply regrets this unfortunate mistake.<br><br>We are initiating immediate action to ensure that this error does not recur.<br><span style="font-style: italic;">[Evan] Like what?&nbsp; Maybe train people to review their query results and follow "normal process"?</span><br><br>The University of Maryland values the critical importance of your personal information.<br><br>We strongly recommend that you take appropriate precautions to mask, black out or destroy this document after use.<br><br>In unfortunate situations like this, it is possible that dishonest people may contact you asking for personal information in the guise of offering assistance from the University.<br><span style="font-style: italic;">[Evan] Equally unfortunate is the fact that there are a lot of dishonest people.</span><br><br>Please note that the University WILL NOT contact you by phone, e-mail or in any other way requesting personal information regarding this incident.<br><br>Please do not release any personal information in response to contacts claiming to be from the University.<br><br>In response to this incident, the University, and specifically the Department of Transportation Services, has moved to severely restrict access to sensitive student and faculty/staff information; we believe the fewer individuals who have access to this data will only increase our ability to protect sensitive information.<br><br>If individuals feel that they would like to take extra steps beyond the fraud alert, the University has arranged with Equifax to make available, at no cost to them, a 12-month service that includes credit monitoring, customer care, fraud expense reimbursement insurance and access to their credit report.<br><br>If you have not received this mailer and are unsure if you are included in the affected group, please call toll-free 1(877) 935-2428, Monday - Friday, 8:30 a.m. - 5 p.m. EST.<br><br><span style="font-weight: bold;">You may contact us in one of the following ways:</span><br>By telephone: Toll-free 1(877) 935-2428, Monday-Friday, 8:30 a.m. - 5 p.m. EST<br>Via e-mail: parkingmailer@umd.edu<br>Mailing address: Regents Drive Garage, Building #202, College Park, MD 20742<br><br><span style="font-weight: bold;">Commentary:</span><br>The lack of attention to detail coupled with lack of control leads to an increase of risk of confidential information disclosure.&nbsp; Not all that uncommon. <br><br><b>Past Breaches:</b><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/18/umd.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 05:18:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/university">university</category>
      <category domain="http://securityratty.com/tag/maryland">maryland</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/university identification">university identification</category>
      <category domain="http://securityratty.com/tag/university community">university community</category>
      <category domain="http://securityratty.com/tag/social security">social security</category>
      <category domain="http://securityratty.com/tag/addressees social security">addressees social security</category>
      <category domain="http://securityratty.com/tag/recipient social security">recipient social security</category>
      <source url="http://breachblog.com/2008/07/18/umd.aspx">Mailing error at the University of Maryland exposes student information</source>
    </item>
    <item>
      <title><![CDATA[Houston law firm threw confidential client information in the trash]]></title>
      <link>http://securityratty.com/article/f6684ed1c67a7acb138958de524dcb1a</link>
      <guid>http://securityratty.com/article/f6684ed1c67a7acb138958de524dcb1a</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/15/08

Organization
Weber Law Firm

Contractor/Consultant/Branch
his wife

Victims
Clients

Number Affected
hundreds

Types of Data
personal financial...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/weber.jpg" width="200" align="right" height="60"><font size="2"><b>Date Reported: </b><br>7/15/08<br><br><b>Organization: </b><br><a href="http://weberlaw.com/">Weber Law Firm</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>"his wife"<br><br><span style="font-weight: bold;">Victims:</span><br>Clients<br><br><span style="font-weight: bold;">Number Affected:</span><br>"hundreds"<br><br><span style="font-weight: bold;">Types of Data:</span><br>"personal financial records, documents with Social Security numbers, people's medical files and more"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"HOUSTON -- Harris County Sheriff's deputies uncovered hundreds of people's personal financial files that had been discarded in a dumpster in northwest Houston on Monday."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.khou.com/business/stories/khou080711_tj_recordsfound.57f842ba.html">KHOU-TV News (original)</a> <br><a href="http://www.khou.com/business/stories/khou080716_tj_filesdumped.6221053b.html">KHOU-TV News (follow-up)</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Jeremy Desel, KHOU-TV<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Harris County Sheriff's deputies uncovered hundreds of people's personal financial files that had been discarded in a dumpster in northwest Houston on Monday.<br><br>The records were mostly bankruptcy case files from a Houston attorney's office that found their way into a dumpster belonging to a Houston day care.<br><span style="font-style: italic;">[Evan] There is little doubt about the sensitivity of the information found in a person's bankruptcy files.&nbsp; Don't you think that an attorney should know better?</span><br><br>The discovery came in a trash bin in the 9100 block of Jones Road, with box after box of records including personal financial records, documents with Social Security numbers, people's medical files and more.<br><br>When the sheriff's office first arrived, the responding deputies had no idea what to do with the records. <br><br>So, they called the law office from where the records had come from. 11 News called the law offices of William Weber as well.<br><span style="font-style: italic;">[Evan] Mr. Weber's </span><a style="font-style: italic;" href="http://weberlaw.com/attorneys-staff.htm">bio</a><span style="font-style: italic;"> is pretty extensive.</span><br><br>Weber, who eventually arrived to pick up the discarded records, told both 11 News and the sheriff's office that it was "no big deal"<br><span style="font-style: italic;">[Evan] Obviously, this answer probably doesn't go over very well.&nbsp; In hindsight, I am guessing that Mr. Weber wishes he could take these words back.</span><br><br>Still, at the insistence of the sheriff's office, Weber did arrive to pick the boxes up.<br><br>Weber had a different answer for 11 News when he showed up to retrieve the 32 boxes.<br><br>"It's a mistake," he said. "We regret it. We regret it. They weren't intended to be put here. I didn't put them here. It was a misunderstanding between me and my wife."<br><span style="font-style: italic;">[Evan] Ugh.&nbsp; Blaming the wife would not be a good idea in my house, even if it were my her fault.</span><br><br>He added it was a one-time problem.<br><br>But he also said his firm does not have a policy for disposing of sensitive documents. <br>"No, I do not. I don't think there is a formal disposal policy. Legally," he answered. <br><br>Don't tell that to Radio Shack or Select Medical Corporation. Both settled lawsuits with the Texas Attorney General's Office this week for violating the Texas ID Theft Law that was passed in 2005.<br><br>It requires businesses to destroy any documents that contain sensitive information. Select Medical dumped 4,000 documents in its own dumpster, but did not destroy them first.<br><br>Both companies settled this week with the state for hundreds of thousands of dollars in fines.<br><span style="font-style: italic;">[Evan] Don't forget about </span><a style="font-style: italic;" href="http://www.oag.state.tx.us/oagNews/release.php?id=2519">EZMONEY, L.P. and EZPAWN L.P.</a><span style="font-style: italic;">&nbsp; They agreed to pay $660,000 to the Texas Attorney General.&nbsp; Don't mess with Texas!</span><br><br>However, it's not just a civil law question. It is also an ethics question. <br><br>"If a customer of Radio Shack had an interest in privacy and an interest to have their identity protected (and) not just tossed to the wind, I can assure you that a medical provider or a lawyer has a higher duty," said 11 News legal expert Gerald Treece.<br><br>The sheriff's office is looking into the possibility laws were broken by throwing away the records in that dumpster, but were unsure if anything illegal happened.<br><br>As a matter of fact, there's a good possibility no laws were broken.<br><span style="font-style: italic;">[Evan] Not criminal.&nbsp; This case may be ripe for a civil proceeding, however.</span><br><br>Weber spent several minutes loading the boxes into his car, but he also spent a lot of time avoiding the 11 News cameras as he picked up the discarded records.<br><br>Eventually, he left the scene, leaving a few boxes behind when he was confronted by 11 News cameras.<br><br>In his rush to get away, a box was left on the trunk lid of his vehicle and some of the papers inside flew out as he sped off.<br><span style="font-style: italic;">[Evan] Embarrassed?</span><br><br>Weber told 11 News that all the documents were shredded on Wednesday morning.<br><span style="font-style: italic;">[Evan] Any thought given to notifying the affected individuals?&nbsp; If not, it is probably too late now.</span><br><br>Weber also said he has talked with an attorney at the attorney general's office and told them he would cooperate fully. <br><br>11 News also spoke with one of the clients whose file was found in the dumpster on Monday. She said she's angry and feels betrayed.<br><br><span style="font-weight: bold;">Commentary:</span><br>We have read about organizations dumping sensitive confidential information in dumpsters before, but this is the first time I have read about a lawyer being responsible (or his wife).&nbsp; Mistakes do happen, but I question how much of a mistake this actually was due to Mr. Weber's initial "no big deal" reaction. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/17/weber.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Thu, 17 Jul 2008 10:59:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/houston">houston</category>
      <category domain="http://securityratty.com/tag/weber">weber</category>
      <category domain="http://securityratty.com/tag/weber wishes">weber wishes</category>
      <category domain="http://securityratty.com/tag/houston attorney">houston attorney</category>
      <category domain="http://securityratty.com/tag/bankruptcy">bankruptcy</category>
      <category domain="http://securityratty.com/tag/khou-tv news">khou-tv news</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/bankruptcy files">bankruptcy files</category>
      <category domain="http://securityratty.com/tag/william weber">william weber</category>
      <source url="http://breachblog.com/2008/07/17/weber.aspx">Houston law firm threw confidential client information in the trash</source>
    </item>
    <item>
      <title><![CDATA[Indiana State University professor's laptop is stolen]]></title>
      <link>http://securityratty.com/article/ac01a165449e657f832374db2c405cad</link>
      <guid>http://securityratty.com/article/ac01a165449e657f832374db2c405cad</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/15/08

Organization
Indiana State University

Contractor/Consultant/Branch
None

Victims
students who took economics classes from 1997 through the...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/indianastate.jpg" width="137" align="right" height="48"><font size="2"><b>Date Reported: </b><br>7/15/08<br><br><b>Organization: </b><br><a href="http://www.indstate.edu/home.htm">Indiana State University</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>"students who took economics classes from 1997 through the spring semester 2008"<br><br><span style="font-weight: bold;">Number Affected:</span><br>"more than 2,500"<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, grades, e-mail addresses and student identification numbers"*<br><br><font size="1">*Until 2003, student identification numbers were the equivalent of each student’s Social Security number.</font><br><br><span style="font-weight: bold;">Breach Description:</span><br>"A password-protected laptop computer containing personal information for current and former Indiana State University students was stolen during the weekend, the university reported Tuesday."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www1.indstate.edu/laptopsecurity/">Indiana State University</a> <br><a href="http://www.wthitv.com/Global/story.asp?S=8684098&amp;nav=menu593_1">Associated Press via WTHI Channel 10 News</a> <br><a href="%20http://www.chicagotribune.com/news/chi-ap-in-isu-stolenlaptop,0,1255776.story">Associated Press via Chicago Tribune</a><br><br><span style="font-weight: bold;">Report Credit:</span><br>Indiana State University<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>A password-protected laptop computer containing personal information for current and former Indiana State University students was stolen during the weekend, the university reported Tuesday.<br><span style="font-style: italic;">[Evan] What do you suppose the purpose of the "password-protected" mention is?&nbsp; I hope it is not meant to reassure anyone that the information is safe.&nbsp; For those of you that do not know, password-protection is easily bypassed and in the opinion of many information security professionals (this one included), does NOT provide adequate protection for confidential information.</span><br><br>While there is no evidence to suggest that password security was breached, the university is taking the precaution of notifying all affected students for whom it has current contact information.<br><span style="font-style: italic;">[Evan] If someone were to breach the "password security", what evidence would the school see?&nbsp; None.&nbsp; There would be no evidence (except locally on the laptop) if the local password store had been compromised.&nbsp; The school no longer has possession of the laptop, so the school would have no evidence.</span><br><br>The laptop contained data for students who took economics classes from 1997 through the spring semester 2008, estimated at more than 2,500 individuals.<br><br>If you took an economics class during this time period, but did not receive a letter, please call the Registrar’s Office to verify that you were on the list, and to update your address so that we may send you a letter.<br><span style="font-style: italic;">[Evan] Contact information for the Registrar's Office, click </span><a style="font-style: italic;" href="http://www1.indstate.edu/registrar/">here</a><span style="font-style: italic;">.</span><br><br>The information includes names, grades, e-mail addresses and student identification numbers.<br><br>Beginning in 2003, use of social security numbers as student ID numbers was discontinued in favor of university-specific identification numbers.<br><span style="font-style: italic;">[Evan] A sound security decision by the university would have been to follow up with a project to identify and remove Social Security numbers already held as student IDs.&nbsp; Maybe it was, but the information on this laptop was missed.</span><br><br>The theft occurred Saturday while the professor was traveling in southern Indiana<br><br>the professor was traveling with his family and briefly left the computer unattended<br><span style="font-style: italic;">[Evan] A laptop can grow legs in a flash.&nbsp; A person doesn't need to leave a laptop unattended for very long for it to disappear.</span><br><br>The incident occurred on July 12, 2008 and was reported to university officials on July 14, 2008.<br><br>The incident was reported immediately to the appropriate law enforcement agency and early Monday to university officials.<br><br>The extent of the information contained on the computer was not determined until Monday night.<br><br>Faculty and staff are being reminded that university policy prohibits the storage of private, sensitive data on portable computers.<br><span style="font-style: italic;">[Evan] Excellent policy provision.&nbsp; Policy does little if it is not communicated, enforced, audited against, and improved.&nbsp; Where was the failure in the breach?&nbsp; Was the policy not communicated to this professor, and thus he/she was not aware?</span><br><br>In addition, laptops provided to faculty are equipped with several security measures including encryption and a bio-metric fingerprint reader to prevent access by anyone other than the assigned user.<br><span style="font-style: italic;">[Evan] An excellent standard (or procedure).</span><br><br>Approximately 500 ISU faculty members have laptop computers.<br><br>The university is reviewing its procedures to ensure compliance with existing policies, said Interim President C. Jack Maynard, the university’s provost and vice president for academic affairs<br><br><span style="font-weight: bold;">From the FAQs:</span><br><br>Q: What can someone do with a stolen SSN?<br>A: "With just a SSN there is little anyone can do in the way of setting up a false identity or securing credit. Generally an identity thief would need more information and documentation to set up false credit.<br><span style="font-style: italic;">[Evan] A SSN needs to be held in strict confidentiality in today's financial, employment, health, and other systems.&nbsp; It is often used for identification and authentication.&nbsp; Once an identity thief has a SSN, the owner of that SSN is now a prime target because the thief has the most confidential piece of information (ingredient) in the identity theft recipe.&nbsp; The rest of the information is typically easier to come by, i.e. name, address, employer, etc.&nbsp; It is true that an SSN alone is not enough information to commit identity theft, but it is an EXCELLENT start.</span><br><br><span style="font-weight: bold;">Commentary:</span><br>We can assume that the school knows the risks involved in storing confidential information on a poorly protected laptop.&nbsp; Otherwise, they probably wouldn't have policy and procedure against it.&nbsp; The school's statements that are meant to minimize the risk, seemingly without fact, are disappointing. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/17/indianastate.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Thu, 17 Jul 2008 05:29:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/university">university</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/information includes names">information includes names</category>
      <category domain="http://securityratty.com/tag/university students">university students</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/laptop">laptop</category>
      <category domain="http://securityratty.com/tag/evan contact information">evan contact information</category>
      <category domain="http://securityratty.com/tag/university policy prohibits">university policy prohibits</category>
      <source url="http://breachblog.com/2008/07/17/indianastate.aspx">Indiana State University professor's laptop is stolen</source>
    </item>
    <item>
      <title><![CDATA[A backup tape is stolen from Greensboro Gynecology Associates]]></title>
      <link>http://securityratty.com/article/50667ca11f139e2009a7776a17ed3db5</link>
      <guid>http://securityratty.com/article/50667ca11f139e2009a7776a17ed3db5</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/15/08

Organization
Greensboro Gynecology Associates

Contractor/Consultant/Branch
None

Victims
Physicians, staff members, and patients

Number...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/gga.jpg" width="70" align="right" height="70"><font size="2"><b>Date Reported: </b><br>7/15/08<br><br><b>Organization: </b><br><a href="http://www.greensborogynassoc.medem.com/">Greensboro Gynecology Associates</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Physicians, staff members, and patients<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, addresses, Social Security numbers, employers, insurance companies, policy numbers and family members"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"GREENSBORO - Patients at a Greensboro doctors’ office have been notified that their personal information - including Social Security numbers and addresses - was stolen in May."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.news-record.com/content/2008/07/15/article/security_breach_puts_patients_of_greensboro_gynecology_at_risk">News &amp; Record</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Ryan Seals, News &amp; Record<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>In a letter mailed to patients, Greensboro Gynecology Associates said a backup tape of their computer database was stolen.<br><span style="font-style: italic;">[Evan] Does "their computer database" include billing information and other confidential information other than personally identifiable information?</span><br style="font-style: italic;"><br>The letter was dated June 16, but some letters weren't postmarked until July 9.<br><br>The medical practice said a backup tape of patient information was stolen on May 29 from an employee who was taking the tape to an off-site storage facility for safekeeping.<br><span style="font-style: italic;">[Evan] I wonder what type of off-site storage facility.&nbsp; Some of the small businesses that I have encountered consider an employee's home to be an "off-site" storage facility.</span><br style="font-style: italic;"><br>The stolen information included patients' name, address, Social Security number, employer, insurance company, policy numbers and family members.<br><br>The tape did not include treatment or specific medical data.<br><br>"We are very concerned about this theft, as we too are victims," Pat Higgins, the practice's administrator, wrote in an e-mail Tuesday. "We are notifying our present and former patients. ..."<br><br>The practice at 719 Green Valley Road Suite 305 said personal information for its physicians and other staff members also was on the stolen tape.<br><br>the case is under investigation<br><br>did not respond to inquiries about how many patients were affected, how the theft occurred and whether anything else was taken<br><br>The practice's letter said the theft had been reported to police. However, officials with the Greensboro Police Department and the Guilford County Sheriff's Office said they had no such report on file.<br><span style="font-style: italic;">[Evan] This is interesting news.</span><br><br>The data was not encrypted, but Greensboro Gynecology Associates said the stolen data isn't likely to be accessed.<br><br>"We have consulted with several computer security experts, and they have advised it is highly unlikely the tapes can be accessed because of the program used and the language (the information) is written in," according to a recording on a hotline set up to address patients' concerns.<br><span style="font-style: italic;">[Evan] Who are these several computer security "experts'?&nbsp; I hate to disagree, but...&nbsp; The assessment is based on "the program used and the language" that the archived information is written in.&nbsp; Really?&nbsp; How hard is it to obtain the necessary hardware and software to access the information?&nbsp; Someone interested in accessing the tape could conceivably flip the data protection tab on the tape (to prevent data corruption through inadvertent writes), download some of the more popular backup software programs, buy a compatible drive (stolen or on eBay), and go to town.&nbsp; Couldn't they?&nbsp; Backup Exec is a very popular backup program.&nbsp; Anyone can download a 60-day trial for free.&nbsp; More talented professionals have even more sophisticated methods of accessing data on tape. </span><br style="font-style: italic;"><br>Greensboro Gynecology Associates said they are consulting with computer security experts to prevent similar thefts in the future.<br><span style="font-style: italic;">[Evan] I kind of hope that they are not consulting with the same computer security "experts" referenced above.</span><br style="font-style: italic;"><br>"We sincerely regret and apologize that this incident occurred," the letter said<br><br><span style="font-weight: bold;">Commentary:</span><br>Many backup software solutions include the option to encrypt the written data built-in.&nbsp; Why not use it?<br><br>Greensboro Gynecology Associates has established a hotline for concerned patients.&nbsp; The phone number is (336) 544-4590.&nbsp;&nbsp; The hotline asks patients to leave their name and telephone number for a staff member to return their call. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/16/gga.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Wed, 16 Jul 2008 12:16:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/greensboro gynecology">greensboro gynecology</category>
      <category domain="http://securityratty.com/tag/greensboro">greensboro</category>
      <category domain="http://securityratty.com/tag/tape">tape</category>
      <category domain="http://securityratty.com/tag/backup tape">backup tape</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/specific medical data">specific medical data</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/computer security">computer security</category>
      <source url="http://breachblog.com/2008/07/16/gga.aspx">A backup tape is stolen from Greensboro Gynecology Associates</source>
    </item>
    <item>
      <title><![CDATA[Are Stolen Credit Card Details Getting Cheaper?]]></title>
      <link>http://securityratty.com/article/a67e13e215d163e122340bffab059502</link>
      <guid>http://securityratty.com/article/a67e13e215d163e122340bffab059502</guid>
      <description><![CDATA[What is shaping the prices of stolen credit card details? The investments the cybercriminals or real life scammers ( through credit card cloning or ATM skimming ) put into the process of obtaining the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div>
<div class="separator" style="text-align: center; clear: both;"></div>
<a href="http://bp3.blogger.com/_wICHhTiQmrA/SHzyYjwnXTI/AAAAAAAAB6c/9rHV8A0Ggz4/s1600-h/ccz.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SHzyYjwnXTI/AAAAAAAAB6c/WQG5_Cal0xY/s200-R/ccz.JPG" style="border: 0pt none ;" /></a>What is shaping the prices of stolen credit card details? The investments the cybercriminals or real life scammers ( through <a href="http://ddanchev.blogspot.com/2007/02/credit-card-data-cloning-tactic.html">credit card cloning</a> or <a href="http://www.snopes.com/fraud/atm/atmcamera.asp">ATM skimming</a>) put into the process of obtaining the details, or can we even talk about investments being made where an experienced scammer has just purchased 1GB of raw credit cards data from a novice botnet master who isn't really aware of the actual value of his "botnet output"?<br />
<br />
Depends on which economic theory you believe in, or whether or not you'll take the "bottom-up approach" or the "top-down" one. And since I'm not aware of the existence of "the invisible hand of the underground market" and centralized power to increase the supply or decrease it to boost prices for the stolen credit card details, also indicating the existence of underground cartels putting everyone in a "price taker" position.<br />
<br />
The basics of demand and supply for anything underground will always apply unless of course, The more they want, the cheaper it gets, the less they want, the higher the price on per credit card basis gets, since the investment on behalf of the malicious party that originally stolen them is virtually the same, and he can theoretically break-even in every single case since the credit card details were obtained efficiently. It's up to the seller to follow or entirely ignore economic behavior, and do what they feel like doing with this good which must on the other hand reach its market liquidity as soon as possible, else it becomes obsolete. The current market model can be further explained as a good example of competitive equilibrium :<br />
<br />
"<i>Competitive market equilibrium is the traditional concept of economic equilibrium, appropriate for the analysis of commodity markets with flexible prices and many traders, and serving as the benchmark of efficiency in economic analysis. <b>It relies crucially on the assumption of a competitive environment where each trader decides upon a quantity that is so small compared to the total quantity traded in the market that their individual transactions have no influence on the prices.</b></i>"<br />
<br />
This can be easily explained in a single sentence - it's a mess and every participant is doing whatever they want to, so generalizing on the prices charged for stolen credit card numbers would be unrealistic, since it's the price a single seller with no real impact on the "average" market price for the same good. As for the average market price itself, it would be hard to measure it depending on the quality of the sample you want to rely on, since this is a type of market where sellers don't have to report price changes in their goods for the purpose of statistical research.<br />
<br />
<a href="http://www.finjan.com/Content.aspx?id=827#SecurityTrendsReport">A recently released report by Finjan</a>, with whom I've been on the same page of several high profile incidents so far, <a href="http://news.yahoo.com/s/nm/20080715/wr_nm/cybercrime_finjan_dc">touches this very same topic</a> :<br />
<br />
"<i>Prices charged by cybercriminals selling hacked bank and credit card details have fallen sharply as the volume of data on offer has soared, forcing them to look elsewhere to boost profit margins, a new report says. Researchers for Finjan, a Web security firm, said the high volumes traded had led to bank and credit card information becoming "commoditized" - account details with PIN codes that once fetched $100 or more each might now go for $10 or $20. In its latest quarterly survey of Web trends, the California-based company said cybercrime had evolved into "a major shadow economy ruled by business rules and logic that closely mimics the legitimate business world.</i>"<br />
<br />
Excluding the presence of <a href="http://ddanchev.blogspot.com/2008/06/price-discrimination-in-market-for.html">price discrimination</a> for a while, as well as open topic offers in the lines of "how much for X amount of Y?" answered as "how much are you willing to pay?", it's all a matter of the seller in a particular situation.<br />
<br />
Furthermore, in real-life market there's always the scarcity problem, however, in the underground market there's no shortage of resources despite the ever growing wants of the buyers. Generalizing even more, take for instance the butterfly effect of a price change in petrol, and result of which is inevitable increase of prices in every single aspect of your life, but in the underground market mostly due to the malicious economies of scale achieved, a price increase in renting a botnet would have no effect in the prices charged for the stolen credit card details obtained through the infected hosts. How come? Basically, the price and resources for malware infection are prone to decrease, if we take a malware infected host as a static foundation for the basis of any upcoming cybercrime activities using it.<br />
<br />
Perhaps the most disturbing part is that the market for stolen credit card details is so mature, and its entry barriers so low these days, that the confidential data that cannot be efficiently obtained through real-life means like credit card cloning or ATM skimming on a large scale, is now purchased online for the purpose of abusing it in real-life by<a href="http://blog.wired.com/27bstroke6/2008/06/citibank-atm-se.html"> embedding the valid information into plastic cards</a>.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=c5gmVJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=c5gmVJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=yABcqJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=yABcqJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iuXpaj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iuXpaj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Ctkd2j"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Ctkd2j" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KJLEOJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KJLEOJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6teEcJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6teEcJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XpeGzj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XpeGzj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/336435935" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 11:36:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/price">price</category>
      <category domain="http://securityratty.com/tag/average market price">average market price</category>
      <category domain="http://securityratty.com/tag/market price">market price</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/credit card details">credit card details</category>
      <category domain="http://securityratty.com/tag/details">details</category>
      <category domain="http://securityratty.com/tag/market">market</category>
      <category domain="http://securityratty.com/tag/competitive market equilibrium">competitive market equilibrium</category>
      <category domain="http://securityratty.com/tag/credit card basis">credit card basis</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/336435935/are-stolen-credit-card-details-getting.html">Are Stolen Credit Card Details Getting Cheaper?</source>
    </item>
    <item>
      <title><![CDATA[Waukesha County job applicant data exposed in mailing]]></title>
      <link>http://securityratty.com/article/6efea251f53508bced1039830009ef31</link>
      <guid>http://securityratty.com/article/6efea251f53508bced1039830009ef31</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/13/08

Organization
Waukesha County, Wisconsin

Contractor/Consultant/Branch
Crivello Carlson, S.C

Victims
Job applicants from the year 2006

Number...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/waukesha.jpg" width="149" align="right" height="200"><font size="2"><b>Date Reported: </b><br>7/13/08<br><br><b>Organization: </b><br><a href="http://www.waukeshacounty.gov/">Waukesha County, Wisconsin</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.milwlaw.com/index.aspx">Crivello Carlson, S.C.</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Job applicants from the year 2006<br><br><span style="font-weight: bold;">Number Affected:</span><br>"more than 130"<br><br><span style="font-weight: bold;">Types of Data:</span><br>Job applications including, names, addresses, job and education history, salary, and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>"More than 130 people who applied for a job with Waukesha County in 2006 had their Social Security numbers, employment and salary information, addresses and phone numbers and other personal information released to one of the women who applied for the job. "<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.jsonline.com/story/index.aspx?id=772046">Milwaukee Journal Sentinel</a> <br><a href="http://www.newrichmond-news.com/articles/index.cfm?id=87905&amp;section=Wisconsin%20News&amp;property_id=19">New Richmond News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Raquel Rutledge, Milwaukee Journal Sentinel<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Taunya Thomas was horrified when she got a call from a stranger who knew almost everything about her.<br><br>The woman on the phone told Thomas she knew her Social Security number, where she lived and worked, how much money she made and where she went to high school and college. She rattled them off, not missing a single digit or fact.<br><br>She promised she wasn't going to use the information.<br><span style="font-style: italic;">[Evan] Yeah.&nbsp; The government body that exposed the information made the promise that "your Social Security number will remain confidential".&nbsp; So much for promises</span>.<br><br>She was calling, she said, because she wanted Thomas and others to know where she had gotten it.<br><br>She hadn't stolen it. <br><br>Waukesha County sent it to her in the mail, along with the same personal information for more than 130 other people who had all applied for a job with the county in 2006.<br><span style="font-style: italic;">[Evan] What's with Wisconsin and mailing confidential information (in error)?&nbsp; This is the third mailing error reported on The Breach Blog coming out of Wisconsin this year.</span><br><br>The woman on the phone, Bernadine Matthews, too had applied for the position as an economic support specialist.<br><br><img src="http://images.quickblogcast.com/95781-88451/matthews.jpg" width="324" border="0"><br><font size="1">This is Matthews displayed holding the applications.&nbsp; Source: Milwaukee Journal Sentinel</font><br><br>When she didn't get it, she filed a complaint with the Equal Employment Opportunity Commission.<br><br>As part of the complaint and the investigation, the EEOC requested copies of all the applications.<br><br>The law firm representing the county, Crivello Carlson, sent the applications to Matthews.<br><span style="font-style: italic;">[Evan] Really?&nbsp; Any second thoughts about the fact that this may put innocent people at risk?</span><br><br>Waukesha County tried to reclaim the documents sent to Matthews, threatening to get a search warrant and send a lawyer to her house, Matthews said.<br><br>When Matthews refused, they insisted she bring the documents to the law firm so they could white-out the private information in the applications.<br><br>Again, Matthews refused.<br><span style="font-style: italic;">[Evan] At what point does Matthews cross a line.&nbsp; The confidential information on those job applications does NOT belong to her.&nbsp; In my opinion, she has no right to maintain possession of the information.&nbsp; For Matthews to knowingly maintain information that does not belong to her almost seems criminal to me.</span><br><br>The applications would be critical to her discrimination suit, she thought.<br><span style="font-style: italic;">[Evan] So risk the disclosure of senstive information belonging to 130 people for your own benefit?&nbsp; If not criminal, it is certainly selfish.</span><br><br>She quickly hired an attorney, copied the documents and sent a set back to the county. She keeps her copies in an oversize safe-deposit box at her bank, she said.<br><span style="font-style: italic;">[Evan] Who authorized her to make copies?&nbsp; The data owners (victims) certainly did not.</span><br><br>"I'm not going to be like the county," Matthews said. "I'm going to protect the privacy of the information in this box. Obviously they didn't give a darn about the applicants' privacy."<br><br>The Waukesha County employment application specifically states it will protect Social Security numbers.<br><br>"Your Social Security Number will remain confidential and will not be copied or released but is required for applicant tracking purposes," the application reads.<br><br><a href="http://www.milwlaw.com/ourpeople/profile.aspx?id=285&amp;name=Raymond%20J.%20Pollen">Ray Pollen</a>, an attorney with Crivello Carlson, at first said it was no mistake that Matthews received the uncensored applications.<br><span style="font-style: italic;">[Evan] So Mr. Pollen sent the information on purpose.&nbsp; Did he stop to think that there might be a problem here?&nbsp; Did it occur to anyone that they should redact the most sensitive information such as Social Security numbers, or names?</span><br><br>He said it was required under federal law that all parties in an EEOC discrimination complaint receive copies of information requested by the agency investigating. He couldn't point to the specific provision.<br><span style="font-style: italic;">[Evan] Does a specific provision exist?&nbsp; I cannot think of a single purpose that a Social Security number would serve in this case.</span><br><br>Several days later, Pollen said the EEOC had no such requirement.<br><br>"The EEOC is silent on the issue," he said.<br><br>Instead it's the state's Equal Rights Division that requires all parties be copied on information requested by the division but even that provision doesn't mandate that attachments - such as the applications - be included. And, Matthew's case was not filed with the state.<br><br>"We followed the state's protocol," Pollen said.<br><br>P.I. asked: So anyone who applies for a job with Waukesha County could have their private information disclosed to a non-governmental third-party?<br>&nbsp;<br>Pollen answered: "We responded to a federal agency's request for information. . . . In my opinion there was no violation of any law or procedure."<br><span style="font-style: italic;">[Evan] Let's give Mr. Pollen the benefit of the doubt.&nbsp; Let's say that there was no violation of any law or procedure here.&nbsp; There certainly seems to be a violation of trust, a violation of good judgment, and a violation of privacy.&nbsp; The "if the law don't state it, then I must be able to do it" mentality is one of the reasons we have so many laws.&nbsp; Maybe if we used a little more common sense.</span><br><br>Taunya Thomas called the release of her information to a stranger shocking. She said at a minimum the county should have notified her that her information had been compromised.<br><br>"I'm devastated that it's that easy for my information to be disclosed," she said. "For someone to call me and tell me where I worked, where I went to school, recite my Social Security number verbatim to me, that's scary."<br><br><span style="font-weight: bold;">Commentary:</span><br>This is a very frustrating breach to read about.&nbsp; It is frustrating when someone knowingly discloses confidential information and then tries to justify it.&nbsp; Equally frustrating is when a person that has no right to the information refuses to part with it.&nbsp; In the middle of all of this are 130 innocent people.<br><br>I do not claim to know half as much about the law as Mr. Pollen does.&nbsp; His actions may be well within his legal rights for all I know. <br><br><b>Past Breaches:</b><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/15/waukesha.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 04:07:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/job">job</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/county">county</category>
      <category domain="http://securityratty.com/tag/waukesha county">waukesha county</category>
      <category domain="http://securityratty.com/tag/senstive information">senstive information</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/sensitive information">sensitive information</category>
      <category domain="http://securityratty.com/tag/salary information">salary information</category>
      <source url="http://breachblog.com/2008/07/15/waukesha.aspx">Waukesha County job applicant data exposed in mailing</source>
    </item>
    <item>
      <title><![CDATA[Williamson County Schools learns of breach reported nine months ago]]></title>
      <link>http://securityratty.com/article/ab879007319944481d6c7e5668489293</link>
      <guid>http://securityratty.com/article/ab879007319944481d6c7e5668489293</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/11/08

Organization
Williamson County Schools

Contractor/Consultant/Branch
None

Victims
Students

3,052 ACT students and 2,117 students who took the...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/wcs.jpg" width="109" align="right" height="123"><font size="2"><b>Date Reported: </b><br>7/11/08<br><br><b>Organization: </b><br><a href="http://www.wcs.edu/">Williamson County Schools</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Students*<br><br><font size="1">*"3,052 ACT students and 2,117 students who took the second grade test were affected", Source: <a href="http://www.wcs.edu/student_information_conf.htm%20">Student Information News Conference Text 7/11/08</a><br></font> <br><span style="font-weight: bold;">Number Affected:</span><br>5,169<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, testing scores, and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>"FRANKLIN, Tenn.- It now appears a security breach at Williamson County schools was much worse than expected. School officials now say more than 5,000 students may have been affected when a school employee accidently posted their personal information online."<br><br>Reference URL:<br><a href="http://www.wcs.edu/student_information_conf.htm">Williamson County Student Information News Conference</a> <br><a href="http://www.newschannel5.com/Global/story.asp?S=8662746">News Channel 5</a> <br><a href="http://www.wreg.com/Global/story.asp?S=8657599">WREG Channel 3 News</a> <br><a href="http://www.wsmv.com/news/16843341/detail.html#-">WSMV Channel 4 News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Liberty Coalition<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>FRANKLIN, Tenn.- It now appears a security breach at Williamson County schools was much worse than expected. School officials now say more than 5,000 students may have been affected when a school employee accidently posted their personal information online.<br><br>Now the county could lose some federal funding because of the mistake.<br><span style="font-style: italic;">[Evan] Do you really think that this will happen?&nbsp; If we looked deeper into the way the public school systems handle confidential information, half of the school districts would lose funding.&nbsp; Williamson County is in good company across the country.</span><br style="font-style: italic;"><br>The school district had to notify the Department of Education because this was a federal violation.<br><br>Director of Schools, Rebecca Sharber is taking on the responsibility of fixing the problem.<br><br>"I'm the head of the school system. I'm accountable," said Sharber.<br><span style="font-style: italic;">[Evan] What a fantastic statement.&nbsp; Corporate CEOs, non-profit executive directors, etc. ARE ultimately responsible for the protection of information.&nbsp; Ms. Sharber just earned my respect.</span><br style="font-style: italic;"><br>"It certainly is distressing to me that information was ever out there," said Sharber.<br><br>According to school officials, former assessment specialist, Chris Nugent is responsible for the computer mix-up.<br><br>He resigned Friday.<br><br>"Mr. Nugent has resigned his position as Assessment Specialist, effective immediately."<br><br>It was August last year when Nugent mistakenly loaded the info on a personal web page, but he never alerted the district.<br><br>They only found out a couple of weeks ago.<br><br>"A principal who had been contacted by a parent brought this to our attention on June 26th."<br><br>"The information given to us indicated that our assessment specialist, Chris Nugent, was involved. This was the first we had heard of this situation."<br><br>"We began our investigation immediately asking Mr. Nugent to gather all data that could possibly be associated with this situation."<br><br>"We thought at that time he would be able to supply the names of students possibly involved in the most timely manner."<br><br>"When Mr. Nugent was unable to get that information for us, our attorney Jason Golden contacted the Liberty Coalition, the organization that had posted the Internet report presented to us by the principal."<br><span style="font-style: italic;">[Evan] The Liberty Coalition posted the information surrounding the breach in October, 2007, many months before the victims were ever made aware.</span><br style="font-style: italic;"><br>"Yesterday afternoon, the Liberty Coalition was able to provide the names of the students affected."<br><br>"Our investigation indicates that the student information was posted on a private website created by Mr. Nugent sometime during the month of August, 2007."<br><br>"On August 28, 2007, the Liberty Coalition notified Mr. Nugent that private student information was on his web site."<br><br>"On August 29, 2007, the web site was shut down."<br><br>"Mr. Nugent did not notify school authorities."<br><br>"Our investigation has established that Mr. Nugent had confidential student files on the same thumb-drive with his personal files."<br><br>"We believe that when Mr. Nugent uploaded his personal files to a web site he created, he inadvertently uploaded our student files."<br><br>Sharber said the first step will be to look at revising policies on student information.<br><br>They will also pay for fraud alerts for the students.<br><br>It could cost the district hundreds of thousands of dollars to pay for those fraud alerts.<br><br>"I would say to other school districts they need to really, really check their policies and procedures on how student data is being used," said Sharber.<br><span style="font-style: italic;">[Evan] Again, did I mention that I respect Ms. Sharber?&nbsp; This statement is very good advice.</span><br><br>More than 5,000 students had their security information posted.<br><br>Most of those are high school students who took the ACT in the 2006-2007 school year, and second graders who took the TCAP the same year.<br><br>"We have learned that most students who took the second grade TCAP achievement test and most students who took the ACT test during the 2006-07 school year had social security numbers on a private website during August of 2007."<br><span style="font-style: italic;">[Evan] Is there some kind of legal requirement that states that a Social Security number must be tied to test scores, or was this just poor judgment?&nbsp; Are/were Social Security numbers used as student IDs at the district?</span><br style="font-style: italic;"><br>"Our review of the records shows that 3,052 ACT students and 2,117 students who took the second grade test were affected."<br><br>The information was on the internet for about a month.<br><br>"I want to thank the parents of Williamson County Schools for their patience and understanding and the positive suggestions they have shared as we have conducted our investigation and gone public with this information.", said Sharber<br><span style="font-style: italic;">[Evan] The Liberty Coalition went public with </span><a style="font-style: italic;" href="https://www.ssnbreach.org/release.php?g=13">this breach</a><span style="font-style: italic;"> in October, 2007.&nbsp; I appreciate the motives of the Liberty Coalition, but I am not pleased with the way they report breaches.&nbsp; I'll elaborate below in the commentary section.</span><br style="font-style: italic;"><br>"I understand the anxiety that our parents are experiencing.", said Sharber<br><br>"On Monday, we will be calling all parents of students whose social security numbers were exposed to let them know their child was affected, and we will follow up that phone call with a letter."<br><br>"We are working to locate a security company, and at our expense, we will cover the cost of fraud protection for the students affected."<br><span style="font-style: italic;">[Evan] I hope that the school locates a good "security company".&nbsp; Of course </span><a style="font-style: italic;" href="http://www.frsecure.com">FRSecure</a><span style="font-style: italic;"> would be glad to help.&nbsp; I promise to keep the plugs to a minimum <img src="http://breachblog.com/emoticons/smile.png" border="0" />.</span><br style="font-style: italic;"><br><span style="font-weight: bold;">Commentary:</span><br>OK.&nbsp; We all know that a breach affecting kids is especially bad.&nbsp; We all know that we are all human and all humans make mistakes.&nbsp; I presume that there are a number of risky information security behaviors at Williamson County Schools.&nbsp; This risky behavior just so happened to expose personal information online.&nbsp; What other risky behaviors will be addressed at the school district?<br><br>Now about the Liberty Coalition's role.&nbsp; I appreciate the motives of Aaron Titus and the Liberty Coalition.&nbsp; He maintains the SSNBreach.org web site where he publicizes information security breaches that his organization finds (or is informed about).&nbsp; My attention was first drawn to Aaron Titus in August 2007, when he reported the <a href="https://www.ssnbreach.org/release.php?g=1">Louisiana Board of Regents breach</a> affecting ~200,000 people.&nbsp; What drew my attention to his report was not the breach itself, but the way in which it he proceeded to report it.&nbsp; Lyger at Attrition.org covers it well <a href="http://attrition.org/security/rant/z/privacy.html">here</a>.<br><br>In this case, the Liberty Coalition publicly posted this breach in October, 2007 which is more than 9 months before the victims were ever made aware!&nbsp; According to the Liberty Coalition press release; "We updated this press release after becoming aware of Mr. Nugent's relationship with the school district. The Liberty Coalition also worked directly with district officials to help them notify the affected individuals."&nbsp; It would have been nice if the victims were notified prior to a public press release.&nbsp; I wonder why Mr. Nugent's relationship with the school district wasn't known earlier.&nbsp; I don't have the details that the Liberty Coalition does surrounding this breach, so I can only speculate.<br><br>The fact that some breaches are reported on SSNBreach.org prior to notification (in this case nine months), I chose to generally not report them here at The Breach Blog. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/12/wcs.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Sat, 12 Jul 2008 20:12:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/school">school</category>
      <category domain="http://securityratty.com/tag/school students">school students</category>
      <category domain="http://securityratty.com/tag/schools">schools</category>
      <category domain="http://securityratty.com/tag/williamson county schools">williamson county schools</category>
      <category domain="http://securityratty.com/tag/williamson county">williamson county</category>
      <category domain="http://securityratty.com/tag/county">county</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/school authorities">school authorities</category>
      <category domain="http://securityratty.com/tag/school district">school district</category>
      <source url="http://breachblog.com/2008/07/12/wcs.aspx">Williamson County Schools learns of breach reported nine months ago</source>
    </item>
    <item>
      <title><![CDATA[Employee fraud hits Baptist Health in Arkansas]]></title>
      <link>http://securityratty.com/article/4227f770b7017f7d953c43516b49d951</link>
      <guid>http://securityratty.com/article/4227f770b7017f7d953c43516b49d951</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/2/08

Organization
Baptist Health

Baptist Health is the largest not-for-profit healthcare organization in Arkansas

Contractor/Consultant/Branch
None...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/baptisthealth.jpg" width="120" align="right" height="274"><font size="2"><b>Date Reported: </b><br>7/2/08<br><br><b>Organization: </b><br><a href="http://www.baptist-health.org/">Baptist Health*</a><br><br><font size="1">*Baptist Health is the largest not-for-profit healthcare organization in Arkansas</font><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Patients<br><br><span style="font-weight: bold;">Number Affected:</span><br>~1,800<br><br><span style="font-weight: bold;">Types of Data:</span><br>"name, address, date of birth, Social Security number, and reason for coming to Baptist Health"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"LITTLE ROCK (AP) - A North Little Rock woman has been arrested for using financial information from patients at Baptist Health to illegally obtain Wal-Mart gift cards for her own use. The hospital has notified about 1,800 patrons of the ID theft."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.wxvt.com/Global/story.asp?S=8609129&amp;nav=menu1344_2">Associated Press via WXVT Channel 15 News</a> <br><a href="http://arkansasmatters.com/content/fulltext/news/?cid=80211">KARK Channel 4 News</a> <br><a href="http://www.nwanews.com/adg/News/230290/">Arkansas Democrat-Gazette</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Toby Manthey, Arkansas Democrat-Gazette<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Baptist Health has sent letters warning about 1,800 patients that the hospital system’s records may have been breached<br><span style="font-style: italic;">[Evan] Uh, "may have been breached"?!</span><br><br>The notification came after the arrest of a Baptist Health employee at a Wal-Mart store on 25 counts of financial identity fraud.<br><span style="font-style: italic;">[Evan] Wouldn't life be grand if we could trust our employees?&nbsp; Maybe, I suppose.</span><br><br>The letters, mailed last week, follow the firing of the woman in early June<br><br>North Little Rock police say Tamara Hill, 30, of that city worked at Baptist Health Medical Center-North Little Rock in the emergency department.<br><br>Hill, an admissions clerk, was arrested May 30 at the Wal-Mart<br><br>Ebony Flowers, 25, also of North Little Rock, was arrested at the store the same day on three counts of identity fraud<br><br>Flowers was listed in a police report as a janitor for the North Little Rock School District<br><span style="font-style: italic;">[Evan] Key word is "was".</span><br><br>Baptist Health recorded more than 950,000 patient visits systemwide in 2007, a number that includes repeat visits.<br><br>Mark Lowman, spokesman for the Little Rock-based Baptist Health system, confirmed that the system fired the employee after notification of the arrest.<br><br>Police reports say the women used a victim’s personal information to obtain temporary Wal-Mart "account authorization numbers" - credit cards, essentially - used to buy Wal-Mart gift cards.<br><br>The victim reported to police that he had not authorized the transactions<br><br>the same victim confirmed he was a Baptist Health patient<br><br>He expressed appreciation of the handling of the case by the system and by the North Little Rock police. <br><br>Among the items found during a search connected with the arrest of Hill was personal information for 24 other people, including "screen shots" - printouts showing the exact appearance of the images on a computer screen - that showed victims’ personal information.<br><span style="font-style: italic;">[Evan] This seems like confirmation that "may have been breached" is not all that accurate.</span><br><br>Also found were four Wal-Mart gift cards and $ 1,490 in cash<br><br>Police found a small bag of marijuana on Flowers, according to the reports. In a search connected with her arrest, they also discovered a. 25-caliber magazine with six bullets, as well as a receipt for four of the gift cards and information on three-identity theft victims.<br><span style="font-style: italic;">[Evan] A thug.</span><br><br>The U. S. Secret Service is helping with the investigation. <br><br>"Due to a breach of our information systems security policies, there is a possibility that some personal information, such as your name, address, date of birth, Social Security number, and reason for coming to Baptist Health, was accessed by an unauthorized person."<br><span style="font-style: italic;">[Evan] This is from the letter to the victims.</span><br><br>No information in the patient’s "medical records" and no information about the patient’s diagnosis or prognosis was accessed<br><br>while no "medical record" information was accessed, the letter mentioned the patient’s "reason for coming" to the system possibly was accessed<br><br>Lowman said a reason stated by a patient using the system isn’t considered medical information because the reason is a layman’s explanation, not one from a medical professional.<br><span style="font-style: italic;">[Evan] This is Mark Lowman, spokesman for the Little Rock-based Baptist Health system</span><br><br>He said the breach wouldn’t violate the Health Insurance Portability and Accountability Act, or HIPAA. <br><br>But Pam Dixon, executive director of the San Diego-based World Privacy Forum, a privacy advocacy group, thinks all the information mentioned in the letter falls under HIPAA.<br><br>"It doesn’t matter that [it’s not ] a prognosis or diagnosis," she said. <br><span style="font-style: italic;">[Evan] Splitting hairs.&nbsp; The bottom line is that confidential personal information was stolen and there are victims.&nbsp; Whether or not it is a HIPAA violation seems somewhat irrelevant.</span><br><br>Dixon found the system’s letter lacking in several respects, such as clarifying the exact meaning of a "reason for coming to Baptist Health." The letter also should have mentioned when and for how long the breach occurred, she said.<br><br>"Almost all breach letters have that," Dixon added.<br><span style="font-style: italic;">[Evan] Almost all breach letters have what?&nbsp; A mention about for how long the breach occurred?&nbsp; I must be reading some of the wrong breach letters because it seems to me that this information is 50/50 at best.&nbsp; Also missing is the "we have no reason to believe that the information will be misused", but this one doesn't fit does it?</span><br><br>Dixon said Baptist Health should have offered in the letter to set up free credit monitoring for victims.<br><span style="font-style: italic;">[Evan] Why?&nbsp; One year (or two) of credit monitoring is almost useless.&nbsp; Credit monitoring alerts a victim after fraud has already occurred and one year (or two) of monitoring is too limited for information that has a much longer lifespan.&nbsp; I guess credit monitoring would be better than nothing, but not by much.</span><br><br>Lowman said the health system continually conducts audits to know which staff members are accessing what information, and whether or not the access is appropriate.<br><span style="font-style: italic;">[Evan] Good!</span><br><br>"We’re always looking to provide better audits and better oversight of private, confidential and protected information," Lowman said.<br><span style="font-style: italic;">[Evan] And Good!</span><br><br><span style="font-weight: bold;">Commentary:</span><br>Preventing and detecting employee fraud has always been a challenge.&nbsp; This doesn't mean we give up though.&nbsp; We have some tools at our disposal such as employee background checks, role-based access control, segregation of duties, and job rotation to name a few.<br><br>I don't think that these two crooks are anything more than common criminals.&nbsp; The fact of the matter is that identity theft and fraud are very easy crimes to commit and require very little skill. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/10/baptisthealth.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Thu, 10 Jul 2008 20:00:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/confidential personal information">confidential personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/baptist health system">baptist health system</category>
      <category domain="http://securityratty.com/tag/health system">health system</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <category domain="http://securityratty.com/tag/victims personal information">victims personal information</category>
      <category domain="http://securityratty.com/tag/employee fraud">employee fraud</category>
      <category domain="http://securityratty.com/tag/baptist health">baptist health</category>
      <category domain="http://securityratty.com/tag/employee">employee</category>
      <source url="http://breachblog.com/2008/07/10/baptisthealth.aspx">Employee fraud hits Baptist Health in Arkansas</source>
    </item>
    <item>
      <title><![CDATA[Simple oversight at TNS Infratest exposes participant information]]></title>
      <link>http://securityratty.com/article/ca9bbb88145ecdbedb20b4a7aa81936a</link>
      <guid>http://securityratty.com/article/ca9bbb88145ecdbedb20b4a7aa81936a</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/4/08

Organization
Taylor Nelson Sofres plc (TNS

Contractor/Consultant/Branch
TNS Infratest

Victims
Survey participants

Number Affected
41,000
...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/tns.jpg" width="98" align="right" height="98"><font size="2"><b>Date Reported: </b><br>7/4/08<br><br><b>Organization: </b><br><a href="http://www.tnsglobal.com/">Taylor Nelson Sofres plc (TNS)</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.tns-infratest.com/">TNS Infratest</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Survey participants<br><br><span style="font-weight: bold;">Number Affected:</span><br>41,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>"Name and address, date of birth, email address and phone numbers", "Some of the data included monthly income, education, bank account information, health insurance data, and which credit cards are used"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"The scientific journal of the Chaos Computer Club (CCC), Die Datenschleuder, reports that market research firm TNS Infratest/Emnid has lost 41,000 private data records of their survey participants."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.ccc.de/updates/2008/umfragetief?language=en">Chaos Computer Club e.V.</a> <br><a href="http://www.theinquirer.net/gb/inquirer/news/2008/07/07/hackers-claim-survey-outfit">The Inquirer</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Chaos Computer Club e.V.<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>TOP MARKET RESEARCH firm TNS Infratest/Emnid has 'lost' 41,000 private data records of its survey participants, the Chaos Computer Club (CCC) has revealed in its official organ Die Datenschleuder.<br><br>As the magazine reports [1], it was possible for participants to read master data records and consumer profiles without bypassing even basic security measures.<br><br>Access to the comprehensive survey results could be gained by simply changing the customer ID number in the browser's address bar.<br><span style="font-style: italic;">[Evan] This type of development mistake too common.&nbsp; The vulnerability is very easy to find by good pen testers and the bad guys.&nbsp; Actually, I am surprised that we don't hear about more of these types of breaches.</span><br><br>Besides name and address, the data records included date of birth, email address and phone number.<br><br>Many records also included very sensitive information: monthly income, education, bank account information, health insurance data, if and which credit cards are used, which electronic devices are used in the household, children's ages and yet more private data.<br><span style="font-style: italic;">[Evan] Clearly this is some very sensitive information, all provided by people completing surveys.</span><br><br>"TNS Infratest made a beginner's mistake in their software development. This is unprofessional, grossly negligent and above all deeply worrying," commented CCC spokesman Dirk Engling regarding the incident.<br><span style="font-style: italic;">[Evan] Mr. Engling is dead on.&nbsp; I couldn't have said it better myself.</span><br><br>"As this information is very sensitive, where abuse such as identity theft or its use in connection with burglary cannot be excluded, THS Infratest needs to inform the victims immediately," he continued<br><br>This case continues a disastrous, never-ending series of information leaks of data held by public and private sector organisations.<br><br>The need for more strict control of sensitive data collections is evidenced by the recent snooping affairs by German Telecom as well as the data leaks from the "Meldeämtern" (registration of address offices). <br><br>It is obvious here that data security only plays a minor role in companies.<br><span style="font-style: italic;">[Evan] Very sad, but very true.&nbsp; Too many organizations still take the wrong view of information security as a "cost center" instead of a business driver.&nbsp; Well designed and managed information security programs, the ones that are aligned with the business and not IT, can actually provide value to the business.</span><br><br>"Especially for companies surveying the most confidential data, the highest security standards have to apply," said Engling.<br><br>The press team of the Chaos Computer Club is available for questions at the following addresses: <br></font><ul><li><font size="2">presse@ccc.de (preferred)</font></li><li>0700-CHAOSFON (0700 - 24267366)<br></li></ul><font size="2"><br><span style="font-weight: bold;">Commentary:</span><br>TNS is a large company, a large company with resources to hire good management, programmers, and information security personnel.&nbsp; What is the excuse for making such a significant, yet simple oversight?&nbsp; There are a number of controls that could have reduced the risk of this occurring.<br><br>One a secondary note, but no less important in my opinion.&nbsp; It seems that people (in general) provide too much information willingly, without understanding what the risks could be.&nbsp; Personally, I rarely complete surveys that ask me for personally identifiable information (name, address, etc.).&nbsp; I suggest that you give some serious thought to providing any of your personal information.&nbsp; Ask yourself if you trust the organization collecting your information.&nbsp; If so, question what your trust is based on.&nbsp; Do NOT hesitate to ask questions and err on the side of caution. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br><br><script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/09/tns.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Wed, 09 Jul 2008 19:37:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/records">records</category>
      <category domain="http://securityratty.com/tag/master data records">master data records</category>
      <category domain="http://securityratty.com/tag/sensitive information">sensitive information</category>
      <category domain="http://securityratty.com/tag/sensitive">sensitive</category>
      <category domain="http://securityratty.com/tag/information leaks">information leaks</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/bank account information">bank account information</category>
      <source url="http://breachblog.com/2008/07/09/tns.aspx">Simple oversight at TNS Infratest exposes participant information</source>
    </item>
  </channel>
</rss>
