<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: nwna]]></title>
    <link>http://securityratty.com/tag/nwna</link>
    <description></description>
    <pubDate>Tue, 04 Mar 2008 07:08:42 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[UPDATE: A computer stolen from Systematic Automation is found]]></title>
      <link>http://securityratty.com/article/9b792cac1e080d88a38cc9805a13d12f</link>
      <guid>http://securityratty.com/article/9b792cac1e080d88a38cc9805a13d12f</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
3/11/08

Organization
19 organizations, including Modesto City Schools , Torrance Unified School District , Clovis Unified School District , Los Angeles...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/sysauto.jpg" align="right" height="51" width="201">
<font size="2"><span style="font-weight: bold;">Date Reported: </span><br>3/11/08<br><br></font><font size="2"><span style="font-weight: bold;">Organization: <br></span></font><span id="RDS_article">19 organizations, including </span><font size="2"><span style="font-weight: bold;"></span><a href="http://www.monet.k12.ca.us/mcsnew/" target="_blank"> Modesto City Schools</a>, </font><font size="2"><a target="_blank" href="http://www.tusd.org/">Torrance Unified School District</a>, </font><font size="2"><a target="_blank" href="http://www.cusd.com/">Clovis Unified School District</a></font>, <font size="2"><a target="_blank" href="http://www.ladwp.com/ladwp/homepage.jsp">Los Angeles Department of Water and Power ("DWP")</a>,&nbsp; and </font><font size="2"><a href="http://www.nestle-watersna.com/">Nestle Waters North America Inc. ("NWNA")</a> </font><font size="2"> </font><br><font size="2"><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://maps.google.com/maps?hl=en&amp;client=opera&amp;rls=en&amp;hs=cvf&amp;um=1&amp;ie=UTF-8&amp;q=Systematic+Automation+Inc.&amp;near=Fullerton,+CA&amp;fb=1&amp;view=text&amp;latlng=33917450,-117929410,15433360472739007456" target="_blank"> Systematic Automation Inc.</a>*<br><br></font><font size="1">*This breach is related to:<br>"<a href="http://breachblog.com/2008/02/12/modschools.aspx">Theft from vendor affects Modesto City Schools employees</a>" dated 2/12/08, <br>"<a href="http://breachblog.com/2008/02/19/dwp.aspx">L.A. Dept. of Water of Power employees exposed</a>" dated 2/19/08, <br>"<a href="http://breachblog.com/2008/02/21/clovis.aspx">Clovis Unified School District employees receive notice</a>" dated 2/21/08<br></font><font size="1">"<a href="http://breachblog.com/2008/02/25/torrance.aspx">Systematic Automation breach continued...</a>" dated 2/22/08</font><font size="1">, and<br></font><font size="1">"<a href="http://breachblog.com/2008/03/04/nestlewaters.aspx">Nestle Waters North America employee affected by Systematic Automation breach</a>" dated 3/4/08<br><br><font size="2"><span style="font-weight: bold;">Update:</span><br></font></font>The Modesto Bee and the Whittier Daily News are reporting that a computer has been recovered from the home of <span id="RDS_article">Todd Irvine, 43 from </span><span id="RDS_article">La Habra.&nbsp; The computer "</span><span id="RDS_article">contained more than 40,000 names, addresses and Social Security numbers of California residents" according to a </span><span id="RDS_article">Fullerton police sergeant.<br><br><span style="font-weight: bold;">Reference URL:<br></span><a href="http://www.whittierdailynews.com/news/ci_8540659">Whittier Daily News</a><br><a href="http://www.modbee.com/local/story/235943.html">Modesto Bee</a><br><br></span><font size="2"><span style="font-weight: bold;">Report Credit:</span><br>Whittier Daily News<br><br></font><font size="2"><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br></font><span id="RDS_article">Fullerton police detectives analyzed data
Tuesday from a stolen computer seized from a La Habra man that
contained more than 40,000 names, addresses and Social Security numbers
of California residents, a sergeant said.<br><br>Todd Irvine, 43, was arrested on Friday after Fullerton detectives served a search warrant at his home in the 700 block of La Serna Avenue, said Fullerton police Sgt. Linda King.<br><br>The computer was stolen in a Feb. 11 commercial burglary of Systematic Automation Inc., a Fullerton data processing firm. The company prints individualized annual statements customized for employees with a summary of their health and other employee benefits, King said.<br><br>Fullerton police received information that the stolen computer was being used to access the Internet, which led to detectives obtaining the search warrant, King said.<br><br>Several other computers also were seized, she said.<br><br>Police are analyzing the computer to determine if the employee information files had been compromised, but no related cases of identity theft have been reported, she said.<br><br>Irvine, a parolee, faces possession of stolen property charges, King said.<br><br><span style="font-weight: bold;">Commentary:<br></span>Mr. Irvine is not a very bright individual, is he?&nbsp; I suspect that the confidential information was not accessed by Mr. Irvine, and I also suspect he didn't even know what he had.<br><br>Police did a superb job by following up on leads and treating this crime very seriously.&nbsp; They should be commended on their work.<br><br>This has been one of the most popular breaches in terms of the number of times the articles have been read, since The Breach Blog was launched in September, 2007<br><br>What should become of Systematic Automations? <span style="font-weight: bold;"><span style="font-weight: bold;"></span><br></span></span><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/03/12/sysautoupdate.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Wed, 12 Mar 2008 09:22:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fullerton police sergeant">fullerton police sergeant</category>
      <category domain="http://securityratty.com/tag/fullerton police">fullerton police</category>
      <category domain="http://securityratty.com/tag/fullerton police sgt">fullerton police sgt</category>
      <category domain="http://securityratty.com/tag/systematic automation">systematic automation</category>
      <category domain="http://securityratty.com/tag/fullerton police detectives">fullerton police detectives</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/systematic automation breach">systematic automation breach</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <source url="http://breachblog.com/2008/03/12/sysautoupdate.aspx">UPDATE: A computer stolen from Systematic Automation is found</source>
    </item>
    <item>
      <title><![CDATA[Nestle Waters North America employee affected by Systematic Automation breach]]></title>
      <link>http://securityratty.com/article/2037234f20d359e95edd4fe9f57e2ede</link>
      <guid>http://securityratty.com/article/2037234f20d359e95edd4fe9f57e2ede</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
2/26/08

Organization
Nestle Waters North America Inc. (&quot;NWNA

Contractor/Consultant/Branch
Systematic Automation

This breach is related to
Theft from...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/nestlewaters.jpg" align="right" height="86" width="116">
<font size="2"><span style="font-weight: bold;">Date Reported: </span><br>2/26/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.nestle-watersna.com/">Nestle Waters North America Inc. ("NWNA")</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://maps.google.com/maps?hl=en&amp;client=opera&amp;rls=en&amp;hs=cvf&amp;um=1&amp;ie=UTF-8&amp;q=Systematic+Automation+Inc.&amp;near=Fullerton,+CA&amp;fb=1&amp;view=text&amp;latlng=33917450,-117929410,15433360472739007456">Systematic Automation</a>*<br><br><font size="1">*This breach is related to:<br>"<a href="http://breachblog.com/2008/02/12/modschools.aspx">Theft from vendor affects Modesto City Schools employees</a>" dated 2/12/08, <br>"<a href="http://breachblog.com/2008/02/19/dwp.aspx">L.A. Dept. of Water of Power employees exposed</a>" dated 2/19/08, and<br>"<a href="http://breachblog.com/2008/02/21/clovis.aspx">Clovis Unified School District employees receive notice</a>" dated 2/21/08<br></font></font><font size="1">"<a href="http://breachblog.com/2008/02/25/torrance.aspx">Systematic Automation breach continued...</a>" dated 2/22/08</font><br><font size="2"><br><span style="font-weight: bold;">Victims:</span><br>Employees of NWNA in 2006<br><br><span style="font-weight: bold;">Number Affected:</span><br>8,245<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, dates of birth, addresses and Social Security numbers.<br><br><span style="font-weight: bold;">Breach Description:</span><br>Computer equipment was stolen from a Nestle Waters North America ("NWNA") vendor, Systematic Automation that contained sensitive personal information belonging to persons employed with NWNA in 2006.&nbsp; Systematic Automation was employed by NWNA to create and distribute employee benefits statements.&nbsp; So far, this single breach has affected persons affiliated with five separate organizations.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://doj.nh.gov/consumer/pdf/nestle_waters.pdf">The New Hampshire State Attorney General breach notification</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>The New Hampshire State Attorney General<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>An Important Notification To Our NWNA Employees:<br>Systematic Automation Inc. ("SAI"), one of our vendors, recently experienced a breakin at their facility in Fullerton, California. Among other things, a desktop computer was stolen that contained a database of sensitive personal informatiion about NWNA employees, including a list of NWNA employees' names, addresses, dates of birth, and social security numbers.<br><br>This database only contained information about employees that were on the payroll as of February 1, 2006. <br><br>The information was password protected, but was not in an encrypted format.<br><span style="font-style: italic;">[Evan] A username and password (most likely Windows operating system) is not adequate protection for confidential information.&nbsp; A Windows XP/2000 password can be bypassed in a matter of minutes.&nbsp; IF the desktop computer were stolen for the information it contained, then we should consider it disclosed.&nbsp; Although encryption is not a perfect solution, it reduces the risk of exposure to an acceptable level in most circumstances.</span><br><br>We use SAI to create and distribute your employee benefits statements. In order for SAI to properly complete the work, we must provide SAI with certain personal information.<br><span style="font-style: italic;">[Evan] Understood, but then SAI needs to be regularly monitored for compliance with policy around the protection of such information.</span><br><br>We deeply regret that this incident occurred and we are talking immediate steps to make sure that something like this does not happen again.<br><br>At this time, we do not know if the thieves stole the computer with the intent to use the personal information for credit fraud purposes or whether this was merely a random criminal act. <br><br>The Fullerton Police Department is investigating the incident and SAI is cooperating fully with the Police Department investigation. <br><br>If this stolen personal information got in the wrong hands, however, you are at risk for identity theft or fraud.<br><br>NWNA will also provide, at no cost to you, one year of premium credit monitoring from Equifax, a leading credit monitoring company. <br><span style="font-style: italic;">[Evan] Equifax is a leading credit monitoring company, but also one of the three credit reporting agencies.&nbsp; It amazes me how Experian has capitalized on the information they collect, manage and sell.&nbsp; They are responsible for keeping accurate records, but at the same time will charge people a fee to make sure that they are doing what they are supposed to be doing.&nbsp; Something should give.</span><br><br>In the near future, instructions on enrollment will be mailed directly to your homes.<br><br>In addition, NWNA is in the process of establishing a hotline to provide you with the resources you need to get your questions answered. <br><br>NWNA sincerely regrets any inconvenience this incident may cause you. <br><br><span style="font-weight: bold;">Commentary:</span><br>As mentioned earlier, NWNA is the fifth known organization to be affected by the single breakin at Systematic Automation.&nbsp; It is becoming more and more clear that Systematic Automation did not follow some information security "best practices" by segmenting confidential customer data and encrypting it at rest.<br><br>I have not yet seen a statement from Systematic Automation. <br><br><span style="font-weight: bold;">Past Breaches:</span><br><span style="font-weight: bold;">Nestle Waters North America:</span><br>Unknown<br><span style="font-weight: bold;">Systematic Automation:</span><br>February, 2008 - <a href="http://breachblog.com/2008/02/25/torrance.aspx">Systematic Automation breach continued...</a> <br>February, 2008 - <a href="http://breachblog.com/2008/02/21/clovis.aspx">Clovis Unified School District employees receive notice</a> <br>February, 2008 - <a href="http://breachblog.com/2008/02/19/dwp.aspx">L.A. Dept. of Water of Power employees exposed</a> <br>February, 2008 - <a href="http://breachblog.com/2008/02/12/modschools.aspx">Theft from vendor affects Modesto City Schools employees</a></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/03/04/nestlewaters.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 04 Mar 2008 07:08:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/systematic automation breach">systematic automation breach</category>
      <category domain="http://securityratty.com/tag/systematic automation">systematic automation</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <category domain="http://securityratty.com/tag/power employees">power employees</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/nwna">nwna</category>
      <source url="http://breachblog.com/2008/03/04/nestlewaters.aspx">Nestle Waters North America employee affected by Systematic Automation breach</source>
    </item>
  </channel>
</rss>
