<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: glaxo]]></title>
    <link>http://securityratty.com/tag/glaxo</link>
    <description></description>
    <pubDate>Fri, 13 Jun 2008 09:10:18 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Severance and personal details of GlaxoSmithKline employees exposed]]></title>
      <link>http://securityratty.com/article/58e91758aa8878262c367e27cb3e449c</link>
      <guid>http://securityratty.com/article/58e91758aa8878262c367e27cb3e449c</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/10/08

Organization
GlaxoSmithKline

Contractor/Consultant/Branch
None

Victims
Employees

Number Affected
more than 500

Types of Data
names, dates of...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/gsk.jpg" align="right" height="51" width="154"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/10/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.gsk.com/">GlaxoSmithKline</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Employees<br><br><span style="font-weight: bold;">Number Affected:</span><br>"more than 500"<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, dates of birth, addresses, pensions, National Insurance numbers and, in some cases, redundancy payouts"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"GLAXO workers fear they will fall victim to fraudsters after their personal details were sent to all staff at the Ulverston site."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.nwemail.co.uk/news/barrow/1.121420">North West Evening Mail</a> <br><a href="http://www.fleetwoodtoday.co.uk/latest-north-west-news/Apology-over-emails.4174723.jp">Fleetwood Weekly News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>North West Evening Mail <br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>GLAXO workers fear they will fall victim to fraudsters after their personal details were sent to all staff at the Ulverston site.<br><br>The emails contained information such as names, dates of birth, addresses, pensions, National Insurance numbers and, in some cases, redundancy payouts, of more than 500 employees.<br><span style="font-style: italic;">[Evan] Have you ever received or sent an email to an entire group of people on accident?&nbsp; It is embarrassing.&nbsp; Add to fact that 500+ of your co-workers were just put at risk of identity theft, and now how do you feel.&nbsp; Chances are greater if you use mail client programs that automatically guess the recipient after only typing a few letters.&nbsp; I wonder if this email was sent by a person or programmatically.</span><br><br>A reliable source, who wishes to remain anonymous, says GSK staff from across south and west Cumbria are up in arms.<br><br>They fear the information has been sent out to all 110,000 employees in the UK and US.<br><span style="font-style: italic;">[Evan] Glaxo officials claim that this was not the case.</span><br><br>And some feel they could become victims of identity theft by cash-strapped workers facing redundancy.<br><br>The mails sent out all with attachments on the intranet<br><br>When they were opened up they gave details of all 540 or so workers. It had such details as their names, address, position and if they had put in for redundancy what figures they could expect.<br><span style="font-style: italic;">[Evan] Wow!&nbsp; The redunancy (or severance) payout information adds a twist to this breach.&nbsp; Not only can the personal information be used for identity theft, but a person getting a larger payout can be targeted specifically.&nbsp; Bad.</span><br style="font-style: italic;"><br>For instance one of the bosses is getting £200,000 redundancy and then a £40,000 a year pension.<br><span style="font-style: italic;">[Evan] That's a helluva payout.&nbsp; That's almost $400,000 and $80,000 US.</span><br><br>A few days after this happened a letter saying sorry was sent out to all employees.<br><span style="font-style: italic;">[Evan] "Sorry" reminds me of what my children say to me when they do something they shouldn't have done.&nbsp; </span><br><br>GSK has apologised to staff, saying it regrets the incident and has made steps to make sure the breach is never repeated.<br><span style="font-style: italic;">[Evan] How will GSK ensure that this breach is never repeated?</span><br><br>The firm claims only Ulverston workers had access to the information.<br><br>Ulverston site director Richard Pamenter say in the letter to Glaxo employees, obtained by The Evening Mail:<br><br>"I wanted to make sure you were made aware that information has been inadvertently released on both the GSK e-mail and intranet systems, which if used inappropriately, could permit access to certain personal information for staff.<br><br>"If any of these documents are used inappropriately, this could allow access to information on individuals’ date of birth, job grade, National Insurance number and home address.<br><br>"Additionally, for some staff, information on pensions, quotes and redundancy payments could be accessed. We have removed the information source from the intranet and are currently progressing the removal of documents and relevant attachments from the company email.<br><br>"We very much regret this incident has occurred and I would like to apologise unreservedly for any embarrassment or inconvenience caused."<br><br><span style="font-weight: bold;">Commentary:</span><br>This breach was not widely covered in the press and the information we know is very limited.&nbsp; I'm going to presume that this breach was the result of an employee mistake. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/13/glaxo.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Fri, 13 Jun 2008 09:10:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/details">details</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <category domain="http://securityratty.com/tag/personal details">personal details</category>
      <category domain="http://securityratty.com/tag/staff">staff</category>
      <category domain="http://securityratty.com/tag/fear">fear</category>
      <category domain="http://securityratty.com/tag/glaxo workers fear">glaxo workers fear</category>
      <category domain="http://securityratty.com/tag/gsk staff">gsk staff</category>
      <source url="http://breachblog.com/2008/06/13/gsk.aspx">Severance and personal details of GlaxoSmithKline employees exposed</source>
    </item>
  </channel>
</rss>
