<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: fullerton]]></title>
    <link>http://securityratty.com/tag/fullerton</link>
    <description></description>
    <pubDate>Tue, 12 Feb 2008 12:03:09 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[UPDATE: A computer stolen from Systematic Automation is found]]></title>
      <link>http://securityratty.com/article/9b792cac1e080d88a38cc9805a13d12f</link>
      <guid>http://securityratty.com/article/9b792cac1e080d88a38cc9805a13d12f</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
3/11/08

Organization
19 organizations, including Modesto City Schools , Torrance Unified School District , Clovis Unified School District , Los Angeles...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/sysauto.jpg" align="right" height="51" width="201">
<font size="2"><span style="font-weight: bold;">Date Reported: </span><br>3/11/08<br><br></font><font size="2"><span style="font-weight: bold;">Organization: <br></span></font><span id="RDS_article">19 organizations, including </span><font size="2"><span style="font-weight: bold;"></span><a href="http://www.monet.k12.ca.us/mcsnew/" target="_blank"> Modesto City Schools</a>, </font><font size="2"><a target="_blank" href="http://www.tusd.org/">Torrance Unified School District</a>, </font><font size="2"><a target="_blank" href="http://www.cusd.com/">Clovis Unified School District</a></font>, <font size="2"><a target="_blank" href="http://www.ladwp.com/ladwp/homepage.jsp">Los Angeles Department of Water and Power ("DWP")</a>,&nbsp; and </font><font size="2"><a href="http://www.nestle-watersna.com/">Nestle Waters North America Inc. ("NWNA")</a> </font><font size="2"> </font><br><font size="2"><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://maps.google.com/maps?hl=en&amp;client=opera&amp;rls=en&amp;hs=cvf&amp;um=1&amp;ie=UTF-8&amp;q=Systematic+Automation+Inc.&amp;near=Fullerton,+CA&amp;fb=1&amp;view=text&amp;latlng=33917450,-117929410,15433360472739007456" target="_blank"> Systematic Automation Inc.</a>*<br><br></font><font size="1">*This breach is related to:<br>"<a href="http://breachblog.com/2008/02/12/modschools.aspx">Theft from vendor affects Modesto City Schools employees</a>" dated 2/12/08, <br>"<a href="http://breachblog.com/2008/02/19/dwp.aspx">L.A. Dept. of Water of Power employees exposed</a>" dated 2/19/08, <br>"<a href="http://breachblog.com/2008/02/21/clovis.aspx">Clovis Unified School District employees receive notice</a>" dated 2/21/08<br></font><font size="1">"<a href="http://breachblog.com/2008/02/25/torrance.aspx">Systematic Automation breach continued...</a>" dated 2/22/08</font><font size="1">, and<br></font><font size="1">"<a href="http://breachblog.com/2008/03/04/nestlewaters.aspx">Nestle Waters North America employee affected by Systematic Automation breach</a>" dated 3/4/08<br><br><font size="2"><span style="font-weight: bold;">Update:</span><br></font></font>The Modesto Bee and the Whittier Daily News are reporting that a computer has been recovered from the home of <span id="RDS_article">Todd Irvine, 43 from </span><span id="RDS_article">La Habra.&nbsp; The computer "</span><span id="RDS_article">contained more than 40,000 names, addresses and Social Security numbers of California residents" according to a </span><span id="RDS_article">Fullerton police sergeant.<br><br><span style="font-weight: bold;">Reference URL:<br></span><a href="http://www.whittierdailynews.com/news/ci_8540659">Whittier Daily News</a><br><a href="http://www.modbee.com/local/story/235943.html">Modesto Bee</a><br><br></span><font size="2"><span style="font-weight: bold;">Report Credit:</span><br>Whittier Daily News<br><br></font><font size="2"><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br></font><span id="RDS_article">Fullerton police detectives analyzed data
Tuesday from a stolen computer seized from a La Habra man that
contained more than 40,000 names, addresses and Social Security numbers
of California residents, a sergeant said.<br><br>Todd Irvine, 43, was arrested on Friday after Fullerton detectives served a search warrant at his home in the 700 block of La Serna Avenue, said Fullerton police Sgt. Linda King.<br><br>The computer was stolen in a Feb. 11 commercial burglary of Systematic Automation Inc., a Fullerton data processing firm. The company prints individualized annual statements customized for employees with a summary of their health and other employee benefits, King said.<br><br>Fullerton police received information that the stolen computer was being used to access the Internet, which led to detectives obtaining the search warrant, King said.<br><br>Several other computers also were seized, she said.<br><br>Police are analyzing the computer to determine if the employee information files had been compromised, but no related cases of identity theft have been reported, she said.<br><br>Irvine, a parolee, faces possession of stolen property charges, King said.<br><br><span style="font-weight: bold;">Commentary:<br></span>Mr. Irvine is not a very bright individual, is he?&nbsp; I suspect that the confidential information was not accessed by Mr. Irvine, and I also suspect he didn't even know what he had.<br><br>Police did a superb job by following up on leads and treating this crime very seriously.&nbsp; They should be commended on their work.<br><br>This has been one of the most popular breaches in terms of the number of times the articles have been read, since The Breach Blog was launched in September, 2007<br><br>What should become of Systematic Automations? <span style="font-weight: bold;"><span style="font-weight: bold;"></span><br></span></span><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/03/12/sysautoupdate.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Wed, 12 Mar 2008 09:22:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fullerton police sergeant">fullerton police sergeant</category>
      <category domain="http://securityratty.com/tag/fullerton police">fullerton police</category>
      <category domain="http://securityratty.com/tag/fullerton police sgt">fullerton police sgt</category>
      <category domain="http://securityratty.com/tag/systematic automation">systematic automation</category>
      <category domain="http://securityratty.com/tag/fullerton police detectives">fullerton police detectives</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/systematic automation breach">systematic automation breach</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <source url="http://breachblog.com/2008/03/12/sysautoupdate.aspx">UPDATE: A computer stolen from Systematic Automation is found</source>
    </item>
    <item>
      <title><![CDATA[Nestle Waters North America employee affected by Systematic Automation breach]]></title>
      <link>http://securityratty.com/article/2037234f20d359e95edd4fe9f57e2ede</link>
      <guid>http://securityratty.com/article/2037234f20d359e95edd4fe9f57e2ede</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
2/26/08

Organization
Nestle Waters North America Inc. (&quot;NWNA

Contractor/Consultant/Branch
Systematic Automation

This breach is related to
Theft from...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/nestlewaters.jpg" align="right" height="86" width="116">
<font size="2"><span style="font-weight: bold;">Date Reported: </span><br>2/26/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.nestle-watersna.com/">Nestle Waters North America Inc. ("NWNA")</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://maps.google.com/maps?hl=en&amp;client=opera&amp;rls=en&amp;hs=cvf&amp;um=1&amp;ie=UTF-8&amp;q=Systematic+Automation+Inc.&amp;near=Fullerton,+CA&amp;fb=1&amp;view=text&amp;latlng=33917450,-117929410,15433360472739007456">Systematic Automation</a>*<br><br><font size="1">*This breach is related to:<br>"<a href="http://breachblog.com/2008/02/12/modschools.aspx">Theft from vendor affects Modesto City Schools employees</a>" dated 2/12/08, <br>"<a href="http://breachblog.com/2008/02/19/dwp.aspx">L.A. Dept. of Water of Power employees exposed</a>" dated 2/19/08, and<br>"<a href="http://breachblog.com/2008/02/21/clovis.aspx">Clovis Unified School District employees receive notice</a>" dated 2/21/08<br></font></font><font size="1">"<a href="http://breachblog.com/2008/02/25/torrance.aspx">Systematic Automation breach continued...</a>" dated 2/22/08</font><br><font size="2"><br><span style="font-weight: bold;">Victims:</span><br>Employees of NWNA in 2006<br><br><span style="font-weight: bold;">Number Affected:</span><br>8,245<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, dates of birth, addresses and Social Security numbers.<br><br><span style="font-weight: bold;">Breach Description:</span><br>Computer equipment was stolen from a Nestle Waters North America ("NWNA") vendor, Systematic Automation that contained sensitive personal information belonging to persons employed with NWNA in 2006.&nbsp; Systematic Automation was employed by NWNA to create and distribute employee benefits statements.&nbsp; So far, this single breach has affected persons affiliated with five separate organizations.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://doj.nh.gov/consumer/pdf/nestle_waters.pdf">The New Hampshire State Attorney General breach notification</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>The New Hampshire State Attorney General<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>An Important Notification To Our NWNA Employees:<br>Systematic Automation Inc. ("SAI"), one of our vendors, recently experienced a breakin at their facility in Fullerton, California. Among other things, a desktop computer was stolen that contained a database of sensitive personal informatiion about NWNA employees, including a list of NWNA employees' names, addresses, dates of birth, and social security numbers.<br><br>This database only contained information about employees that were on the payroll as of February 1, 2006. <br><br>The information was password protected, but was not in an encrypted format.<br><span style="font-style: italic;">[Evan] A username and password (most likely Windows operating system) is not adequate protection for confidential information.&nbsp; A Windows XP/2000 password can be bypassed in a matter of minutes.&nbsp; IF the desktop computer were stolen for the information it contained, then we should consider it disclosed.&nbsp; Although encryption is not a perfect solution, it reduces the risk of exposure to an acceptable level in most circumstances.</span><br><br>We use SAI to create and distribute your employee benefits statements. In order for SAI to properly complete the work, we must provide SAI with certain personal information.<br><span style="font-style: italic;">[Evan] Understood, but then SAI needs to be regularly monitored for compliance with policy around the protection of such information.</span><br><br>We deeply regret that this incident occurred and we are talking immediate steps to make sure that something like this does not happen again.<br><br>At this time, we do not know if the thieves stole the computer with the intent to use the personal information for credit fraud purposes or whether this was merely a random criminal act. <br><br>The Fullerton Police Department is investigating the incident and SAI is cooperating fully with the Police Department investigation. <br><br>If this stolen personal information got in the wrong hands, however, you are at risk for identity theft or fraud.<br><br>NWNA will also provide, at no cost to you, one year of premium credit monitoring from Equifax, a leading credit monitoring company. <br><span style="font-style: italic;">[Evan] Equifax is a leading credit monitoring company, but also one of the three credit reporting agencies.&nbsp; It amazes me how Experian has capitalized on the information they collect, manage and sell.&nbsp; They are responsible for keeping accurate records, but at the same time will charge people a fee to make sure that they are doing what they are supposed to be doing.&nbsp; Something should give.</span><br><br>In the near future, instructions on enrollment will be mailed directly to your homes.<br><br>In addition, NWNA is in the process of establishing a hotline to provide you with the resources you need to get your questions answered. <br><br>NWNA sincerely regrets any inconvenience this incident may cause you. <br><br><span style="font-weight: bold;">Commentary:</span><br>As mentioned earlier, NWNA is the fifth known organization to be affected by the single breakin at Systematic Automation.&nbsp; It is becoming more and more clear that Systematic Automation did not follow some information security "best practices" by segmenting confidential customer data and encrypting it at rest.<br><br>I have not yet seen a statement from Systematic Automation. <br><br><span style="font-weight: bold;">Past Breaches:</span><br><span style="font-weight: bold;">Nestle Waters North America:</span><br>Unknown<br><span style="font-weight: bold;">Systematic Automation:</span><br>February, 2008 - <a href="http://breachblog.com/2008/02/25/torrance.aspx">Systematic Automation breach continued...</a> <br>February, 2008 - <a href="http://breachblog.com/2008/02/21/clovis.aspx">Clovis Unified School District employees receive notice</a> <br>February, 2008 - <a href="http://breachblog.com/2008/02/19/dwp.aspx">L.A. Dept. of Water of Power employees exposed</a> <br>February, 2008 - <a href="http://breachblog.com/2008/02/12/modschools.aspx">Theft from vendor affects Modesto City Schools employees</a></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/03/04/nestlewaters.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 04 Mar 2008 07:08:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/systematic automation breach">systematic automation breach</category>
      <category domain="http://securityratty.com/tag/systematic automation">systematic automation</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <category domain="http://securityratty.com/tag/power employees">power employees</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/nwna">nwna</category>
      <source url="http://breachblog.com/2008/03/04/nestlewaters.aspx">Nestle Waters North America employee affected by Systematic Automation breach</source>
    </item>
    <item>
      <title><![CDATA[Systematic Automations breach continued...]]></title>
      <link>http://securityratty.com/article/32ca930ef71fb370c271d0c682b7a939</link>
      <guid>http://securityratty.com/article/32ca930ef71fb370c271d0c682b7a939</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
2/22/08

Organization
Torrance Unified School District

Contractor/Consultant/Branch
Systematic Automation

This breach is related to
Theft from vendor...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/torrance.jpg" align="right" height="180" width="174"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>2/22/08<br><br><span style="font-weight: bold;">Organization: </span><br><a target="_blank" href="http://www.tusd.org/">Torrance Unified School District</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a target="_blank" href="http://maps.google.com/maps?hl=en&amp;client=opera&amp;rls=en&amp;hs=cvf&amp;um=1&amp;ie=UTF-8&amp;q=Systematic+Automation+Inc.&amp;near=Fullerton,+CA&amp;fb=1&amp;view=text&amp;latlng=33917450,-117929410,15433360472739007456">Systematic Automation</a>* <br><br><font size="1">*This breach is related to:<br>"<a target="_blank" href="http://breachblog.com/2008/02/12/modschools.aspx">Theft from vendor affects Modesto City Schools employees</a>" dated 2/12/08, <br>"<a target="_blank" href="http://breachblog.com/2008/02/19/dwp.aspx">L.A. Dept. of Water of Power employees exposed</a>" dated 2/19/08, and<br>"<a target="_blank" href="http://breachblog.com/2008/02/21/clovis.aspx">Clovis Unified School District employees receive notice</a>" dated 2/21/08</font><br><br><span style="font-weight: bold;">Victims:</span><br>Employees<br><br><span style="font-weight: bold;">Number Affected:</span><br>~2,200**<br><br><font size="1">**Over 17,000 total (and counting)</font><br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, addresses, dates of birth and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>Computer equipment was stolen from a Torrance Unified School District vendor, Systematic Automation that contained sensitive personal information belonging to employees of the 33 campus district.&nbsp; Systematic Automation manages employee benefit information, and the district is the fourth reported organization affected by the loss.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a target="_blank" href="http://www.dailybreeze.com/ci_8342542">The dailybreeze.com online news story</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Shelly Leachman, dailybreeze.com, also submitted to The Breach Blog by an informed reader<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>Personal information about 2,200 Torrance Unified School District staffers was housed on a hard drive recently stolen from an Orange County company that helps agencies administer employee health benefits.<br><br>Names, addresses, birth dates and Social Security numbers were among the personal details stored on equipment at Systematic Automation Inc. of Fullerton, district officials confirmed Friday.<br><br>"I'm a little disappointed with my school district for not having done something about it. They have had a lot of time to respond to us," said Irmi Lake, a 10-year Torrance Unified para-educator and chapter vice president of her union, the California School Employees Association.<br><br>Noting that members of her union "don't fault the district for the incident," Lake added, "I was hoping that we would get some more assistance to help all the employees in the district."<br><span style="font-style: italic;">[Evan] The district <span style="font-weight: bold;">DOES </span>share some fault in this breach.&nbsp; The personal information was given to the district with the assumption that the district would protect the information.&nbsp; The responsibility for the protection of information does not cease because the district contracted a third-party to work with the information.&nbsp; Vendors, contractors and consultants must all comply with an organization's information security policies and practices.&nbsp; The organization must demand compliance and audit vendors on a regular basis.</span><br><br>Business chief Don Stabler said Friday that letters addressing the theft and including information about fraud alerts are en route to all those affected. <br><br>"We're not downplaying it at all," Stabler said, noting that such a breach is a first for the 33-campus district. "It is a serious situation, and we're doing everything we can to notify our employees and give them some information so they can protect themselves."<br><br>Torrance Unified has contracted with Systematic Automation for about one year, Stabler said, explaining that the company digitally enrolls district staffers for health benefits.<br><br>In addition to the data-containing hard drive, three monitors were stolen.<br><br><span style="font-weight: bold;">Commentary:</span><br>As stated earlier in the posting, this is the fourth organization affected by this single breach.&nbsp; I wonder if any one of the organizations inspected Systematic Automation's information security practices.&nbsp; If they had, would they have known that Systematic Automation stores sensitive personal information entrusted to multiple organizations on a shared unencrypted hard drive?<br><br>A couple of tips if you are contacting with a company that you share confidential information with (beyond what was shared in the commentary <a target="_blank" href="http://breachblog.com/2008/02/19/dwp.aspx">here</a>):<br><br></font><ol><li><font size="2">Demand that your vendors segment your confidential information from those of their other clients.</font></li><li>Demand encryption of confidential information while in transit and at rest.<br></li></ol><font size="2"><br>Of course there are no guarantees, but each security best practice followed decreases the amount of risk to unauthorized disclosure of confidential information. <br><br><span style="font-weight: bold;">Past Breaches:</span><br><span style="font-weight: bold;">Torrance Unified School District:</span><br>Unknown<br><span style="font-weight: bold;">Systematic Automation:</span><br>February, 2008 - <a target="_blank" href="http://breachblog.com/2008/02/21/clovis.aspx">Clovis Unified School District employees receive notice</a> <br>February, 2008 - <a target="_blank" href="http://breachblog.com/2008/02/19/dwp.aspx">L.A. Dept. of Water of Power employees exposed</a> <br>February, 2008 - <a target="_blank" href="http://breachblog.com/2008/02/12/modschools.aspx">Theft from vendor affects Modesto City Schools employees</a> </font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/02/25/torrance.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 25 Feb 2008 07:28:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/district">district</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/33-campus district">33-campus district</category>
      <category domain="http://securityratty.com/tag/district officials">district officials</category>
      <category domain="http://securityratty.com/tag/enrolls district staffers">enrolls district staffers</category>
      <category domain="http://securityratty.com/tag/information security practices">information security practices</category>
      <category domain="http://securityratty.com/tag/school district vendor">school district vendor</category>
      <source url="http://breachblog.com/2008/02/25/torrance.aspx">Systematic Automations breach continued...</source>
    </item>
    <item>
      <title><![CDATA[Clovis Unified School District employees receive notice]]></title>
      <link>http://securityratty.com/article/662c821c98ea5a31b7ba3df83725eae5</link>
      <guid>http://securityratty.com/article/662c821c98ea5a31b7ba3df83725eae5</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
2/16/08

Organization
Clovis Unified School District

Contractor/Consultant/Branch
Systematic Automation

This breach is related to
Theft from vendor...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/clovis.jpg" align="right" height="76" width="200">
<font size="2"><span style="font-weight: bold;">Date Reported: </span><br>2/16/08<br><br><span style="font-weight: bold;">Organization: </span><br><a target="_blank" href="http://www.cusd.com/">Clovis Unified School District</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a target="_blank" href="http://maps.google.com/maps?hl=en&amp;client=opera&amp;rls=en&amp;hs=cvf&amp;um=1&amp;ie=UTF-8&amp;q=Systematic+Automation+Inc.&amp;near=Fullerton,+CA&amp;fb=1&amp;view=text&amp;latlng=33917450,-117929410,15433360472739007456">Systematic Automation</a>* <br><font size="1"><br>*This breach is related to:<br>"<a target="_blank" href="http://breachblog.com/2008/02/12/modschools.aspxdated%202/12/08">Theft from vendor affects Modesto City Schools employees</a>" dated 2/12/08, and<br>"<a target="_blank" href="http://breachblog.com/2008/02/19/dwp.aspx">L.A. Dept. of Water of Power employees exposed</a>" dated 2/19/08</font><br><br><span style="font-weight: bold;">Victims:</span><br>Employees<br><br><span style="font-weight: bold;">Number Affected:</span><br>~4,000**<br><br><font size="1">**Over 15,000 total (and counting)</font><br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, addresses and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>Computer equipment was stolen from a Clovis Unified School District vendor, Systematic Automation that contained sensitive personal information belonging to employees of the district.&nbsp; Systematic Automation manages employee benefit information, and the district is the third reported organization affected by the loss.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a target="_blank" href="http://www.cbs47.tv/news/local/story.aspx?content_id=1ba0136a-9863-4073-b33c-807a493ba9fc">CBS Channel 47 News online story</a> <br><a target="_blank" href="http://www.fresnobee.com/263/story/396688.html">The Fresno Bee online story</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>CBS Channel 47 News<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Clovis Unified School District employees were notified that a computer stolen this week from a Fullerton company contained personal information -- including Social Security numbers -- for about 4,000 district employees.<br><br>police do not believe the intent of the burglary was to steal identity information<br><span style="font-style: italic;">[Evan] I don't know how you would determine intent based on the limited information available.&nbsp; At some point in time thieves are going to figure out that there is a heckuva lot more to gain by using the stolen information than there is in the pawning off the hardware.</span><br style="font-style: italic;"><br>Fullerton police say the computers are password protected but that doesn't mean the code can't be cracked<br><span style="font-style: italic;">[Evan] This is very true.&nbsp; Most Windows passwords can be bypassed in less than five minutes.</span><br><br>the district has recommended that employees establish fraud alerts on their credit files<br><br>The district also held two fraud-prevention seminars for employees Wednesday, with seven more planned during the next week.<br><br>Employee information for Clovis Unified and 15 other organizations was jeopardized when Systematic Automation of Fullerton was burglarized about 4:30 a.m. Monday.<br><span style="font-style: italic;">[Evan] Wow.&nbsp; 15 organizations and their employees are at risk due to one breach.&nbsp; We know of at least three; Clovis Unified School District, Los Angeles Department of Water and Power ("DWP"), and Modesto City Schools.</span><br style="font-style: italic;"><br>District employees were alerted in an e-mail about 3:30 p.m. Tuesday<br><span style="font-style: italic;">[Evan] Quick notification.&nbsp; This was a good decision on the part of district management</span><br><br>The stolen computer contained Clovis Unified employee names, addresses and salaries, as well as Social Security numbers. It did not contain birth dates or other personal information.<br><br>Systematic Automation handles the online benefits enrollment for Clovis Unified employees and publishes information on what benefits each employee receives<br><span style="font-style: italic;">[Evan] Might need to change "handles" to "handled".&nbsp; I wonder how this single breach affects Systematic Automation's business viability.</span><br style="font-style: italic;"><br>The police believe the computers contained tens of thousands of pieces of information.<br><br><span style="font-weight: bold;">Commentary:</span><br>What is there to say that hasn't already been said in the two previous postings?&nbsp; Did any of the 15 organizations audit Systematic Automation's information security practices? <br><br><span style="font-weight: bold;">Past Breaches:</span><br><span style="font-weight: bold;">Clovis Unified School District:</span><br>Unknown<br><span style="font-weight: bold;">Systematic Automation:</span><br>February, 2008 - <a target="_blank" href="http://breachblog.com/2008/02/19/dwp.aspx">L.A. Dept. of Water of Power employees exposed</a> <br>February, 2008 - <a target="_blank" href="http://breachblog.com/2008/02/12/modschools.aspx">Theft from vendor affects Modesto City Schools employees</a></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/02/21/clovis.aspx" type="text/javascript" charset="utf-8"></script>
]]></content:encoded>
      <pubDate>Wed, 20 Feb 2008 22:57:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/district">district</category>
      <category domain="http://securityratty.com/tag/district employees">district employees</category>
      <category domain="http://securityratty.com/tag/school district">school district</category>
      <category domain="http://securityratty.com/tag/district management">district management</category>
      <category domain="http://securityratty.com/tag/school district vendor">school district vendor</category>
      <category domain="http://securityratty.com/tag/school district employees">school district employees</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <source url="http://breachblog.com/2008/02/21/clovis.aspx">Clovis Unified School District employees receive notice</source>
    </item>
    <item>
      <title><![CDATA[L.A. Dept. of Water of Power employees exposed]]></title>
      <link>http://securityratty.com/article/f70613215508b1a91be5d9f49aab2c95</link>
      <guid>http://securityratty.com/article/f70613215508b1a91be5d9f49aab2c95</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
2/15/08

Organization
Los Angeles Department of Water and Power (&quot;DWP

Contractor/Consultant/Branch
Systematic Automation Inc

This breach appears to be...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/dwp.jpg" align="right" height="70" width="168"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>2/15/08<br><br><span style="font-weight: bold;">Organization: </span><br><a target="_blank" href="http://www.ladwp.com/ladwp/homepage.jsp">Los Angeles Department of Water and Power ("DWP")</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a target="_blank" href="http://maps.google.com/maps?hl=en&amp;client=opera&amp;rls=en&amp;hs=cvf&amp;um=1&amp;ie=UTF-8&amp;q=Systematic+Automation+Inc.&amp;near=Fullerton,+CA&amp;fb=1&amp;view=text&amp;latlng=33917450,-117929410,15433360472739007456*">Systematic Automation Inc.</a> <br><br><font size="1">*This breach appears to be related to "<a target="_blank" href="http://breachblog.com/2008/02/12/modschools.aspx">Theft from vendor affects Modesto City Schools employees</a>" dated 2/12/08</font><br><br><span style="font-weight: bold;">Victims:</span><br>Employees<br><br><span style="font-weight: bold;">Number Affected:</span><br>8,275<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, Social Security numbers, dates of birth, employee identification numbers, salaries, work locations, deferred compensation balances (but not account numbers), insurance plan coverage and health care benefits selection"<br><br><span style="font-weight: bold;">Breach Description:</span><br>Computer equipment was stolen from a Los Angeles Department of Water and Power vendor, Systematic Automation that contained sensitive personal information belonging to every employee of the utility.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a target="_blank" href="http://www.dailynews.com/news/ci_8277304">Los Angeles Daily News online story</a> <br><a target="_blank" href="http://www.latimes.com/news/printedition/california/la-me-dwp16feb16,1,22139.story?ctrack=1&amp;cset=true">Los Angeles Times online story</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Beth Barrett, Los Angeles Daily News<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Computer equipment containing the private financial data of every employee of the Los Angeles Department of Water and Power was stolen earlier this week, prompting the utility to pay for a credit monitoring service for each of its 8,275 workers.<br><br>DWP General Manager H. David Nahai sent a letter to employees Wednesday informing them of the "possible security breach" and of steps being taken to safeguard them from the risk of identity theft.<br><br>DWP officials said the theft occurred at Systematic Automation Inc. in Fullerton and is being investigated by Fullerton law enforcement.<br><span style="font-style: italic;">[Evan] From last week's Modesto City Schools breach, in which "A computer hard drive containing sensitive personal information belonging to Modesto City School district employees was stolen from Systematic Automation Inc. in Fullerton, California."&nbsp; Do you suppose this means that Systematic Automation was storing multiple client data sets on the same drive?</span><br><br>The data that was taken on active DWP employees included names, Social Security numbers, dates of birth, employee identification numbers, salaries, work locations, deferred compensation balances (but not account numbers), insurance plan coverage and health care benefits selection.<br><br>Nahai said the DWP had contracted with the company to print retirement booklets showing employees' benefits and other information<br><br>"This kind of work is done by very specialized companies, and I think many companies contract out this kind of work," he said. (Nahai)<br><span style="font-style: italic;">[Evan] This may justify why DWP sent the information out to a vendor, but it does not justify the breach or the lack of oversight (vendor management).&nbsp; Vendors trusted with confidential information <span style="font-weight: bold;">MUST </span>be held to the same strict standards as the company itself.</span><br><br>Nahai said the DWP was taking "extraordinary steps to protect our employees.<br><br>He said the data is encrypted and that the thieves may not be able to extract it.<br><span style="font-style: italic;">[Evan] Encrypting the information is a very good call by DWP, but according to the Modesto City Schools breach, "Snelling said the district sent the employee information in an encrypted format to Systematic Automation, where it apparently was stored on the computer in an unencrypted format."&nbsp; I would be surprised if the DWP information were not in a similar state.</span><br><br>The utility's Retirement Office (213-367-1692) also has made arrangements for a one-year subscription to a credit monitoring service for employees.<br><br>"It's in the very early stages of the investigation, and very early to point fingers," he said. (Nahai)<br><br>DWP spokesman Joe Ramallo said the utility had no evidence that the missing information had been misused<br><br>"We're required by law to notify our employees that this theft occurred," he said. "But we don't have any knowledge at this point that the data was the target, and law enforcement said they don't believe that it is."<br><br>a spokesman for the International Brotherhood of Electrical Workers Local 18, the union that represents DWP employees, said Friday that his workers were "shocked and upset" by the loss of the data.<br><br>"They believe this is a direct result of the mania for outsourcing that the DWP has had," said Bob Cherry, a communications consultant for the union. "The DWP should have been paying more attention to the potential impact of sensitive data like this getting sent to outside vendors."<br><span style="font-style: italic;">[Evan] Bob Cherry knows a thing or two.&nbsp; The security of information is the responsibility of the organization to whom it was originally given to by the owner.&nbsp; This is a simple owner/custodian relationship.&nbsp; Just because the custodian did not lose the hard drive directly does not mean that the custodian is not responsible for the breach.</span><br><br>Vince Foley, who serves on the board of the DWP Retired Employees Assn., said he has received anxious calls from retirees. The stolen computer equipment also contained financial data on employees who retired between July 1, 2006, and June 30, 2007.<br><br>Foley said. "DWP's computers are, of course, encrypted and protected. But this is a situation where they had . . . a consultant who's given all this data so they can prepare the [benefits] statements."<br><br><span style="font-weight: bold;">Commentary:</span><br>I wonder how many more organizations are affected by the Systematic Automation burglary.&nbsp; So far, we know of two organizations and over 11,000 affected persons.<br><br>There are lessons to be learned from almost any breach, and it's easier to play the "Monday morning quarterback".&nbsp; Good information security programs recognize the importance of managing security throughout the life-cycle of the information, no matter where it resides.&nbsp; At a minimum:<br><br></font><ol><li><font size="2">Thoroughly evaluate the information security practices of vendors before engaging in formal business agreements.</font></li><li>Information security language should be included in contractual agreements.</li><li>Conduct regular audits of vendors to ensure that they continue to abide by your information security policies, standards, guidelines and procedures.</li><li>If your company engages vendors on a regular basis, formalize the vendor security evaluation, approval and audit process.<br></li></ol><font size="2"><br>These are just some tips that could easily be expanded upon and refined to your individual situation. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Related:<br>February, 2008 - <a target="_blank" href="http://breachblog.com/2008/02/12/modschools.aspx">Theft from vendor affects Modesto City Schools employees</a></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/02/19/dwp.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 19 Feb 2008 14:11:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/employee information">employee information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information security practices">information security practices</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/information security policies">information security policies</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/dwp">dwp</category>
      <category domain="http://securityratty.com/tag/dwp officials">dwp officials</category>
      <category domain="http://securityratty.com/tag/represents dwp employees">represents dwp employees</category>
      <source url="http://breachblog.com/2008/02/19/dwp.aspx">L.A. Dept. of Water of Power employees exposed</source>
    </item>
    <item>
      <title><![CDATA[Theft from vendor affects Modesto City Schools employees]]></title>
      <link>http://securityratty.com/article/592543590c35731d2d9c029ff59afde2</link>
      <guid>http://securityratty.com/article/592543590c35731d2d9c029ff59afde2</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
2/11/08

Organization
Modesto City Schools

Contractor/Consultant/Branch
Systematic Automation Inc

Victims
School district employees

Number Affected...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/modschools.jpg" align="right" height="111" width="120"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>2/11/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.monet.k12.ca.us/mcsnew/" target="_blank"> Modesto City Schools</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://maps.google.com/maps?hl=en&amp;client=opera&amp;rls=en&amp;hs=cvf&amp;um=1&amp;ie=UTF-8&amp;q=Systematic+Automation+Inc.&amp;near=Fullerton,+CA&amp;fb=1&amp;view=text&amp;latlng=33917450,-117929410,15433360472739007456" target="_blank"> Systematic Automation Inc.</a> <br><br><span style="font-weight: bold;">Victims:</span><br>School district employees<br><br><span style="font-weight: bold;">Number Affected:</span><br>3,500<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, addresses, birth dates and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>A computer hard drive containing sensitive personal information belonging to Modesto City School district employees was stolen from Systematic Automation Inc. in Fullerton, California.&nbsp; Systematic Automation Inc. prints annual benefits summaries for employees.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.modbee.com/local/story/208868.html" target="_blank"> The Modesto Bee online story</a> <br><a href="http://www.kcra.com/news/15276289/detail.html" target="_blank"> KCRA Channel 3 News story</a> <br><a href="http://www.news10.net/display_story.aspx?storyid=38353" target="_blank"> ABC News Channel 10 story</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>KCRA Channel 3 News<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>All 3,500 employees were affected by the breach, which happened after a computer drive with names, addresses, birth dates and Social Security numbers was stolen from a Southern California data processing firm in Fullerton.<br><br>Systematic Automation Inc., prints benefits information for employees including health benefits for the district.<br><br>The hard drive and three monitors were stolen at 4:30 a.m. in a "window smash" burglary, said Sgt. Linda King with the Fullerton Police Department.<br><br>An e-mail was sent out to all affected employees.<br><br>Snelling said the district sent the employee information in an encrypted format to Systematic Automation, where it apparently was stored on the computer in an unencrypted format.<br><span style="font-style: italic;">[Evan] Good and bad.&nbsp; Good that the school district encrypted the information before sending it out.&nbsp; Bad that the school either did not communicate it's security expectations well or enforce them through regular audits of vendors.</span><br><br>"We want to do the accountable thing, which is to let everyone know so they can take their own steps to protect themselves," Modesto City Schools Superintendent Arturo Flores said.<br><br>Director of Business Services Dennis Snelling said no cases of identity theft connected with the data breach have been reported.<br><br>"We’re keeping an eye out," Snelling said. "We want our people to be able to protect themselves."<br><br>Snelling said other agencies had their data compromised in the theft, but he did not have details.<br><span style="font-style: italic;">[Evan] Not cool.</span><br><br>Snelling sent a memo by e-mail and hard copy on paper just before 2 p.m. to warn employees and provide information about how to monitor for fraud.<br><br>District officials said they plan to look into the security practices of each agency to which that receives employee information is sent.<br><span style="font-style: italic;">[Evan] Excellent addition to their practices.&nbsp; Vendors and contractors are extensions of the organization.</span><br><br>"We’d certainly be taking that up with Systematic Automation," he said. Employees with concerns can contact Louise Baker, supervisor of payroll and benefits, at 576-4192.<br><br><span style="font-weight: bold;">Victim Reaction:</span><br>"There are a lot of very unhappy people," said Ray Duran, vice president of the Modesto Teachers Association. "I just hate to think all my stuff is out there. We know these things happen. We just hope the district will find a way to remedy the problem."<br><span style="font-style: italic;">[Evan] Unfortunately, there is little remedy for exposed information.&nbsp; Once information has been exposed, it stays exposed.</span><br><br>Sonoma Elementary teacher Judy Pierce said she was pleased at how quickly the district notified district employees and provided steps to help prevent identity theft.<br><br>"I think all of us hope in our lifetime we won’t be faced with these issues," Pierce said. "But (the district) gave us an entire two pages of steps of who to go to, who to contact. It made it very, very easy for us to follow through on it."<br><br><span style="font-weight: bold;">Commentary:</span><br>I am actually impressed with how well the school responded to this breach.&nbsp; It appears that they notified employees in a timely manner.&nbsp; The school also appears to know a thing or two about information security as demonstrated by encrypting the data and now recognizing the importance of evaluating vendor security practices. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/02/12/modschools.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 12 Feb 2008 12:03:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/district officials">district officials</category>
      <category domain="http://securityratty.com/tag/district">district</category>
      <category domain="http://securityratty.com/tag/district employees">district employees</category>
      <category domain="http://securityratty.com/tag/school district">school district</category>
      <category domain="http://securityratty.com/tag/school district employees">school district employees</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/provide information">provide information</category>
      <source url="http://breachblog.com/2008/02/12/modschools.aspx">Theft from vendor affects Modesto City Schools employees</source>
    </item>
  </channel>
</rss>
