<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: dhl]]></title>
    <link>http://securityratty.com/tag/dhl</link>
    <description></description>
    <pubDate>Mon, 14 Jan 2008 09:04:35 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Thousands of Canadian Chrysler Financial customers at risk]]></title>
      <link>http://securityratty.com/article/a7d9492053aec306cf4583b0203cb9bb</link>
      <guid>http://securityratty.com/article/a7d9492053aec306cf4583b0203cb9bb</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
4/22/08

Organization
Chrysler Corporation

Contractor/Consultant/Branch
Chrysler Financial (Canada
United Parcel Service (&quot;UPS

Victims
Canadian...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/chryslerfin.jpg" align="right" height="53" width="149"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>4/22/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.chrysler.com/en/">Chrysler Corporation</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.chryslerfinancial.ca/en/index.jsp">Chrysler Financial (Canada)</a> <br><a href="http://www.ups.com/">United Parcel Service ("UPS")</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Canadian customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>"thousands"<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, addresses and social insurance numbers"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"TORONTO - The lending arm of the Chrysler Corporation says the U-P-S courier service may have lost a data tape containing personal information about thousands of its Canadian customers."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.canada.com/windsorstar/news/story.html?id=6480e2a5-b638-4e57-a7fb-64fc00db8dd8&amp;k=5975">The Windsor Star</a> <br><a href="http://www.thespec.com/News/BreakingNews/article/359214">The Hamilton Spectator</a> <br><a href="http://winnipegsun.com/News/Canada/2008/04/24/5374686.html">Winnipeg Sun</a> <br><a href="http://www.thestar.com/Business/article/418228">Toronto Star</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Dave Hall, The Windsor Star<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>TORONTO - The lending arm of the Chrysler Corporation says the U-P-S courier service may have lost a data tape containing personal information about thousands of its Canadian customers.<br><span style="font-style: italic;">[Evan] In this day, it baffles me that companies still send backup tapes through UPS, DHL, FedEx, etc. without encryption.&nbsp; This is especially difficult for me to comprehend when the company deals with extremely sensitive personal information.&nbsp; In this instance, I don't place much blame on UPS.</span><br><br>The lost information affects Chrysler Financial lease customers across Canada.<br><br>The Office of the Privacy Commissioner of Canada says it is "monitoring" Chrysler's lending arm<br><br>Chrysler Financial also acknowledged yesterday that it waited five weeks or longer to tell customers the tape had been lost or possibly destroyed.<br><br>Chrysler Financial acknowledged it did not inform customers for five weeks or longer about a "destroyed or lost" tape because of an internal search and investigation, noting it didn't want to alarm customers until it exhausted a search with United Parcel Service.<br><span style="font-style: italic;">[Evan] This is a common excuse, but is it a valid one?</span><br><br>The automaker had sent a package with the mainframe data tape from Farmington Hills, Mich., via UPS to a Quebec credit agency when it disappeared in early March.<br><br>The company has not recovered the tape but it found a damaged envelope it was in.<br><br>The tape holds names, addresses and social insurance numbers of customers.<br><br>Jelena Jelich says special computer software and other equipment is needed to access the data.<br><br>"The data tape cannot be easily accessed and requires specialized software and equipment to read but it did contain some personal information that Chrysler Financial had obtained from you,"<br><span style="font-style: italic;">[Evan] A person would need "specialized software" like backup software (Veritas, Commvauly, etc.) and equipment like an appropriate tape drive, I assume.&nbsp; Nothing all that special.&nbsp; The "cannot be easily accessed" claim could be argued.</span><br><br>During the past week, customers have received letters from Chrysler Financial general counsel Brian Chillman informing them of the incident.<br><br>Chillman said the company has no reason to suspect that an unauthorized person has retrieved or is using the personal information.<br><br>"Nonetheless, as a precautionary measure we are alerting you to this recent incident so that you may be watchful for signs of any possible misuse of you personal information by an unauthorized recipient,"<br><span style="font-style: italic;">[Evan] How nice of Chrysler Financial.&nbsp; After all, the information BELONGS to the customers, not the company.</span><br><br>A Chrysler Financial spokeswoman said that after the tape went missing, internal processes were changed and the information is now sent by secure electronic transmissions. UPS is no longer used.<br><span style="font-style: italic;">[Evan] Welcome to 2008, or was it 1995 (the year IPsec RFCs 1825 &amp; 1829 were published)?</span><br><br>"We apologize for any inconvenience or harm this may cause you." <br><br><span style="font-weight: bold;">Victim Reaction:</span><br>Chris Jovanovic, who leases a car from Chrysler, said the company was notified by United Parcel Service about the lost tape on Mar. 12 but a letter from Chrysler Financial dated Mar. 27 didn't arrive in his mailbox until Monday.<br><br>"It's the time frame of notification that's got me upset because if the tape did fall into the wrong hands, they've had six weeks to access the information and do something with it,"<br><br>Jovanovic said he wasn't convinced by Chillman's assurances because "someone who knows what they're doing could probably access the information. Nothing's that secure these days and it annoys me to think that if the tape never shows up, will we be looking over our shoulders for years waiting for the information to be used."<br><br>Jovanovic said he was seeking legal advice to determine his next steps.<br><br><span style="font-weight: bold;">Commentary:</span><br>I don't have much patience or compassion for organizations that send tapes containing gigabytes (and sometimes terabytes) of confidential information through couriers and mail without encryption.&nbsp; Chrysler Financial claims that this is the first time something like this has ever happened.&nbsp; Don't you think that it was just a matter of time? <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/04/30/chryslerfin.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Wed, 30 Apr 2008 18:04:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/chrysler">chrysler</category>
      <category domain="http://securityratty.com/tag/chrysler financial spokeswoman">chrysler financial spokeswoman</category>
      <category domain="http://securityratty.com/tag/chrysler financial">chrysler financial</category>
      <category domain="http://securityratty.com/tag/lost tape">lost tape</category>
      <category domain="http://securityratty.com/tag/tape">tape</category>
      <category domain="http://securityratty.com/tag/chrysler financial claims">chrysler financial claims</category>
      <category domain="http://securityratty.com/tag/data tape">data tape</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <category domain="http://securityratty.com/tag/tape drive">tape drive</category>
      <source url="http://breachblog.com/2008/04/30/chryslerfin.aspx">Thousands of Canadian Chrysler Financial customers at risk</source>
    </item>
    <item>
      <title><![CDATA[Wealthy investor information falls out of DHL van]]></title>
      <link>http://securityratty.com/article/f2ab2f0c1a2327560ebf920d9863141a</link>
      <guid>http://securityratty.com/article/f2ab2f0c1a2327560ebf920d9863141a</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
1/11/08

Organization
Prudential plc

Contractor/Consultant/Branch
DHL International

Victims
wealthy investors

Number Affected
200

Types of Data...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/pru.jpg" align="right" height="50" width="183"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>1/11/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.pru.co.uk/" target="_blank"> Prudential plc</a><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.dhl.co.uk/publish/gb/en.high.html" target="_blank"> DHL International</a><br><br><span style="font-weight: bold;">Victims:</span><br>"wealthy investors"<br><br><span style="font-weight: bold;">Number Affected:</span><br>200<br><br><span style="font-weight: bold;">Types of Data:</span><br>Financial details<br><br><span style="font-weight: bold;">Breach Description:</span><br>A box containing sensitive paperwork related to 200 wealthy investors was found on the side of the road near Reading in Berkshire (UK).&nbsp; The box was in transit from a Prudential building in Reading to a secure storage facility in Essex when it apparently fell out of the DHL courier van.&nbsp; Among the 200 wealthy investors that were affected were three UK national lottery winners.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.thisislondon.co.uk/news/article-23432010-details/Bank" details="" lottery="" winners="" found="" by="" side="" of="" road="" in="" appalling="" new="" security="" blunder="" article.do?expand="true#StartComments" target="_blank"> The London Evening Standard news story</a> <br><a href="http://www.theregister.co.uk/2008/01/14/document_breach_brace/" target="_blank"> The Register Story</a><br><br><span style="font-weight: bold;">Report Credit:</span><br>The London Evening Standard<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Banking details for 200 wealthy people have been found near a motorway sliproad - after apparently falling unnoticed out of a courier's van.<br><span style="font-style: italic;">[Evan] Wealthy people don't like to lose money. <img src="http://breachblog.com/emoticons/wink.png" border="0" /></span><br><br>Among the boxful of Prudential files relating to investments worth many millions of pounds were those reportedly belonging to three National Lottery winners.<br><br>In the box were cheques and other sensitive papers which criminals could potentially have used to hack into customers' accounts.<br><br>The documents were found by a vehicle recovery driver on a roundabout near a sliproad for Junction 11 of the M4 near Reading in Berkshire.<br><br>The box was meant to have been taken by a DHL courier from a Prudential building in Reading to a secure storage facility in Essex.<br><br>"The Pru is clearly not happy at all. It has suspended all use of DHL until the investigation is concluded."<br><br>The box of files are now safely back in the hands of the Prudential.<br><br>Letters were being sent out to all of the 200 customers affected, giving assurances that they would not lose out.<br><br>"Protection of our customers' data is of paramount importance to us and we are contacting them immediately.<br><br>"It was a delivery being made on our behalf to a secure storage facility in Essex and basically the DHL van and the box parted company at some stage during that journey."<br><br>One, Karen Child, who won £8.4 million last year, told the paper after being informed of the blunder: "I feel physically ill."<br><br><span style="font-weight: bold;">Commentary:</span><br>It seems like Prudential was doing the right thing in transporting sensitive documents to a "secure storage facility".&nbsp; The DHL driver appears to have made a mistake in not ensuring that the door of the van was secure.&nbsp; DHL drivers are human too.<br><br>This is not a high-tech breach.<br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/01/14/pru.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 14 Jan 2008 09:04:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dhl van">dhl van</category>
      <category domain="http://securityratty.com/tag/dhl">dhl</category>
      <category domain="http://securityratty.com/tag/dhl courier">dhl courier</category>
      <category domain="http://securityratty.com/tag/van">van</category>
      <category domain="http://securityratty.com/tag/dhl drivers">dhl drivers</category>
      <category domain="http://securityratty.com/tag/dhl courier van">dhl courier van</category>
      <category domain="http://securityratty.com/tag/secure">secure</category>
      <category domain="http://securityratty.com/tag/secure storage facility">secure storage facility</category>
      <category domain="http://securityratty.com/tag/prudential plc">prudential plc</category>
      <source url="http://breachblog.com/2008/01/14/pru.aspx">Wealthy investor information falls out of DHL van</source>
    </item>
  </channel>
</rss>
