<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: interbank]]></title>
    <link>http://securityratty.com/tag/interbank</link>
    <description></description>
    <pubDate>Tue, 15 Apr 2008 19:57:04 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[File containing Interbank FX customer information exposed for almost a year]]></title>
      <link>http://securityratty.com/article/184d08544bae8b30426de5caac87fb7a</link>
      <guid>http://securityratty.com/article/184d08544bae8b30426de5caac87fb7a</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
4/9/08

Organization
Interbank FX, LLC (&quot;IBFX

Contractor/Consultant/Branch
None

Victims
Customers and prospective customers prior to April 2, 2007
...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/interbank.jpg" align="right" height="62" width="169"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>4/9/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="https://secure.ibfx.com/Default.aspx">Interbank FX, LLC ("IBFX")</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Customers and prospective customers prior to April 2, 2007<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>"social security number, driver's license, and passport information, and may also include your Interbank FX account information"<br><br><span style="font-weight: bold;">Breach Description:</span><br>In April, 2007 an employee posted a file to an insecure server that was accessible via the Internet.&nbsp; The file contained personal information belonging to certain persons who applied for an Interbank FX account prior to April, 2007.&nbsp; Interbank FX became aware of the exposure on March 28th, 2008.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://doj.nh.gov/consumer/pdf/interbank.pdf">The New Hampshire State Attorney General breach notification</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>The New Hampshire State Attorney General<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>The letter to victims is signed by Todd B. Crosland, CEO and President of Interbank FX<br><span style="font-style: italic;">[Evan] This fact is important to note.&nbsp; I admire corporate leaders who step up and respond to an incident.&nbsp; Mr. Crosland seems to understand his role very well as it pertains to information security.&nbsp; Business leaders are the people that are ultimately responsible for the security of the organizations they run.</span><br><br>We are writing to inform you of a matter that may affect you. The security of some personal information you provided as you considered our service was inadvertently compromised. <br><br>Interbank FX has thoroughly investigated the matter, has taken immediate steps to protect your information, and is taking the additional precautions outlined in this letter to assist you in monitoring and guarding the security of your personal information.<br><br>The incident involved an electronic file dated April 2, 2007, which contained personal information provided by certain individuals who had applied for an Interbank FX account prior to that date. <br><br>Around that time, an employee uploaded the file to a computer server accessible via the internet. <br><span style="font-style: italic;">[Evan] So, sometime around April, 2007 is the date of the actual exposure.</span><br><br>The employee's action - placing the file outside of the Company's development lab, firewalls and secure computing environment - was contrary to Interbank FX policies and procedures and compromised the security of the information in the file.<br><span style="font-style: italic;">[Evan] I understand what the meaning of this statement is, but I also want to make it clear that a "development lab, firewalls, and secure computing environment" do not ensure security.&nbsp; There is a lot of room for interpretation. </span><br><br>The file contained the information you provided to us when you opened or considered opening an account with us. This may include your social security number, driver's license, and passport information, and may also include your Interbank FX account information.<br><br>Upon learning on March 28, 2008 that this information was available outside our secured computing envirornnent, the Company took immediate steps to secure the information. <br><span style="font-style: italic;">[Evan] The breach was discovered (by Interbank FX) almost a year later.&nbsp; The window of exposure was pretty long.</span><br><br>Within hours of that discovery, all files containing sensitive personal information were removed from the server and brought within the Company's firewalls and electronic security controls. <br><br>We also terminated the employee's access to all personal information in Interbank FX 's files.<br><br>You are receiving this letter because your application information was provided prior to April 2, 2007. <br><br>The incident does not affect anyone who applied for an Interbank FX account after April 2, 2007.<br><br>Interbank FX is committed to protecting your personal information. Thus, we are offering you the opportunity to enroll, at no cost to you, in Equifax Credit Watch(TM) Gold with 3-in-l Monitoring for a one-year period.<br><span style="font-style: italic;">[Evan] Although one-year has become a sort of de-facto standard in breach responses, it is not long enough.&nbsp; A Social Security number is valuable for a much longer period of time.</span> <br><br>We also will reimburse you for the direct cost of any freeze you choose to put on your credit file as a result of this issue. <br><span style="font-style: italic;">[Evan] I though that this statement was interesting.&nbsp; Maybe I don't read breach notifications thoroughly enough, but I don't think I have seen this offer before.</span><br><br>As an additional precaution, we also encourage you to change any password you created for your Interbank FX account prior to April 2, 2007. <br><br>We have established a toll-free hotline (800-550-1571) to answer your questions and assist you in signing up for the Equifax Credit WatchTM program. We ask you to notify us immediately if you notice (or have noticed) any unusual activity in any of your accounts.<br><br>We regret this incident and apologize for any inconvenience.<br><br><span style="font-weight: bold;">Commentary:</span><br>One year of exposure is a very long time for confidential information.&nbsp; I wonder how the company finally learned about the presence of the file(s).&nbsp; What do you suppose are the chances that the employee who uploaded the file:<br><br>1. Was not aware of the "Interbank FX policies and procedures" that pertained to his/her actions?<br>2. Was not aware that the file contained sensitive personal information?<br>3. Was not aware that the server was insecure and accessible publicly?<br>4. All of the above?<br><br>Personnel that handle sensitive information must be trained and re-trained.&nbsp; These personnel must also be reminded regularly through an ongoing awareness program. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/04/15/interbank.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 15 Apr 2008 19:57:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/application information">application information</category>
      <category domain="http://securityratty.com/tag/handle sensitive information">handle sensitive information</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/interbank">interbank</category>
      <category domain="http://securityratty.com/tag/file">file</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <source url="http://breachblog.com/2008/04/15/interbank.aspx">File containing Interbank FX customer information exposed for almost a year</source>
    </item>
  </channel>
</rss>
