<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: penney]]></title>
    <link>http://securityratty.com/tag/penney</link>
    <description></description>
    <pubDate>Fri, 18 Jan 2008 07:24:59 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Another security breach, but this one is different...]]></title>
      <link>http://securityratty.com/article/90d7c103965563fa195dd3b59e703de2</link>
      <guid>http://securityratty.com/article/90d7c103965563fa195dd3b59e703de2</guid>
      <description><![CDATA[Late last week I saw the news around local JC Penney's hit the wire - &quot;Data of 650,000 customers at risk. &quot; Now this situation appears completely different then TJX. The data, and I assume the...]]></description>
      <content:encoded><![CDATA[Late last week I saw the news around local JC Penney's hit the wire - <a href="http://www.scmagazineus.com/Data-of-650000-customers-of-JCPenney-other-retailers-at-risk-after-backup-goes-missing/article/104368/">"Data of 650,000 customers at risk.</a>"   Now this situation appears completely different then TJX.  The data, and I assume the protection of that data, were outsourced. <br /><br />So this begs the question - should it be a requirement for vendors providing services to enterprises that would include sensitive data be certified against ISO 27001?<br /><br />Here is a <a href="http://www.esj.com/Enterprise/article.aspx?EditorialsID=2957">great write-up, case study I came across of a vendor doing this</a>.  Just like we expect vendors to achieve specific Service Level Agreements on availability, performance...shouldn't we be doing the same things around security and risk?<img src="http://feeds.feedburner.com/~r/PracticalRiskManagement/~4/220404572" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jan 2008 10:51:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/include sensitive data">include sensitive data</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/situation appears completely">situation appears completely</category>
      <category domain="http://securityratty.com/tag/expect vendors">expect vendors</category>
      <category domain="http://securityratty.com/tag/vendors">vendors</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/protection">protection</category>
      <category domain="http://securityratty.com/tag/assume">assume</category>
      <source url="http://feeds.feedburner.com/~r/PracticalRiskManagement/~3/220404572/another-security-breach-but-this-one-is.html">Another security breach, but this one is different...</source>
    </item>
    <item>
      <title><![CDATA[J.C. Penney customers affected by lost GE Money backup tape]]></title>
      <link>http://securityratty.com/article/a9d0b61384b46c14779a139d682145cf</link>
      <guid>http://securityratty.com/article/a9d0b61384b46c14779a139d682145cf</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
1/18/08

Update to &quot; GE Money and Iron Mountain unable to locate tape

Organization
J.C. Penney

Contractor/Consultant/Branch
GE Money
Iron Mountain
...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/jcp.jpg" align="right" height="53" width="152"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>1/18/08*<br><br><font size="1">*<span style="font-weight: bold;">Update </span>to "<a href="http://breachblog.com/2008/01/07/gem.aspx" target="_blank"> GE Money and Iron Mountain unable to locate tape</a>" </font><br><br><span style="font-weight: bold;">Organization: </span><br>J.C. Penney<br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>GE Money<br>Iron Mountain<br><br><span style="font-weight: bold;">Victims:</span><br>J.C. Penney customers and the customers of "up to 100 other retailers" which include "many of the large retail organizations"<br><br><span style="font-weight: bold;">Number Affected:</span><br>650,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, addresses, account numbers, Social Security numbers, and other information<br><br><span style="font-weight: bold;">Breach Description:</span><br>GE Money and it's backup storage vendor, Iron Mountain are unable to locate a backup tape.&nbsp; The unencrypted tape contained sensitive personal information belonging to GE Money, J.C. Penney, and up to 100 other retail store customers.&nbsp; The tape was lost in October, 2007.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://ap.google.com/article/ALeqM5iZchJDcVnuQDNPJsok2PSPr5vwRQD8U823R03" target="_blank"> Associated Press Story</a> <br><a href="http://doj.nh.gov/consumer/pdf/ge.pdf" target="_blank"> State of New Hampshire Breach notification dated December 28, 2007</a> <br><a href="http://breachblog.com/2008/01/07/gem.aspx" target="_blank"> Original Breach Blog Report</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>The Associated Press<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Personal information on about 650,000 customers of J.C. Penney and up to 100 other retailers could be compromised after a computer tape went missing.<br><br>GE Money, which handles credit card operations for Penney and many other retailers, said Thursday night that the missing information includes Social Security numbers for about 150,000 people.<br><br>The information was on a backup computer tape that was discovered missing last October. It was being stored at a warehouse run by Iron Mountain Inc., a data storage company, and was never checked out but can't be found either<br><br>This unencrypted tape, which was being retained at a secure, offsite storage facility, included your name, address, and Social Security number, as well as your [CLIENT1] credit card account number<br><br>It was checked into their secure facility and never checked out, and a search of their premises and ours has been unable to locate it.<br><br>there was "no indication of theft or anything of that sort," and no evidence of fraudulent activity on the accounts involved<br><br>Iron Mountain spokesman Dan O'Neill said it would take specialized skills for someone to glean the personal data from the tape.<br><span style="font-style: italic;">[Evan] It also takes specialized skills to walk upright on two feet.&nbsp; If the information on&nbsp; the tape is not encrypted, accessing it is a trivial task.</span><br><br>the company regretted losing the tape, "but because of the volume of information we handle and the fact people are involved, we have occasionally made mistakes."<br><span style="font-style: italic;">[Evan] Mr. O'Neill makes a valid point.&nbsp; Iron Mountain handles millions of tapes.&nbsp; According to their web site, they handle data storage (and protection) for over 90,000 organizations in 26 countries.&nbsp; Eventually a tape will go missing.&nbsp; I don't place much blame on Iron Mountain as I do on GE Money.</span><br><br>declined to identify the other retailers whose customers' information is missing but said "it includes many of the large retail organizations."<br><br>It took GE Money two months to reconstruct the missing tape and identify the people whose information was lost.<br><span style="font-style: italic;">[Evan] Two months is a long time, but I suppose you want to be sure you get it right.</span><br><br>Since December, the company has been notifying consumers in batches of several thousand and telling them to phone a call center set up to deal with the breach. The notification is expected to be completed next week.<br><br>Penney's card holder Elizabeth Rich of Everett, Wash., got one of the GE Money letters saying her name, address and account number may have been compromised. She was told her Social Security number was not on the tape.<br><br>The letter, signed by GE Money President Brent P. Wallace, read in part, "We have no reason to believe that anyone has accessed or misused your information. The pieces of information on the tape would not be enough to open new accounts in your name, and we have implemented internal monitoring to protect your account number from misuse due to this incident."<br><span style="font-style: italic;">[Evan] The "would not be enough to open new accounts in your name" part is because Elizabeth Rich was one of the fortunate persons that did not have her Social Security number on the tape.</span><br><br>Wallace said in the letter that Penney "was in no way responsible for this incident."<br><span style="font-style: italic;">[Evan] I respectfully disagree with this statement.&nbsp; J.C. Penney collected the information from the owner.&nbsp; This puts J.C. Penney into a "data custodian" role.&nbsp; As a data custodian, they have the duty to ensure that the data is protected throughout its lifecycle.&nbsp; J.C. Penney needs to ensure that their partners and vendors adequately secure information.</span><br><br>The Penney name didn't appear on the envelope Rich received, and she thought it was a credit solicitation when she saw the GE Money return address.<br><br>"I think the average consumer has thrown away that GE Money letter because they don't know it's about J.C. Penney," Rich said. "Not everybody opens junk mail."<br><span style="font-style: italic;">[Evan] Do you suppose this was on purpose?&nbsp; Who knows.</span><br><br>Rich said she canceled her Penney card immediately.<br><span style="font-style: italic;">[Evan] This is an EXCELLENT suggestion for all affected customers.&nbsp; Cancelling your card does three things (at least), it protects from credit card fraud (on this card anyway), sends a message to J.C. Penney that they should do more to monitor partners' and vendors' business and security practices, and sends a message to GE Money that they must encrypt confidential data at rest (potentially among other things).</span><br><br><span style="font-weight: bold;">Commentary:</span><br>We originally reported this breach on the Breach Blog a few weeks ago based on information we gleaned from the New Hampshire State Attorney General.&nbsp; This new information helps to clarify some of the missing information.&nbsp; I am sure there will be more to come.<br><br>As I stated earlier in my comments, I don't fault Iron Mountain much for their role in this breach granted they lost the tape.&nbsp; I would expect a certain amount of loss given the nature of their business, the number of tapes they handle, and the fact that people make mistakes.&nbsp; I don't know what kind of excuse GE Money has for not encrypting confidential data at rest.&nbsp; This is a well-known best practice that is preached by most good information security personnel.&nbsp; The fact that the breach notifications sent to customers are not clearly marked as such (according to Elizabeth Rich) only adds insult to injury.<br><br>Contrary to what J.C. Penney may think and what GE Money has stated, J.C. Penney does have responsibility in this breach.&nbsp; To state that J.C. Penney "was in no way responsible for this incident" is false.&nbsp; They have the responsibility to ensure that the information given to them from the owner is handled appropriately.&nbsp; Do they audit their partners' information security practices?&nbsp; Did they know or care that sensitive information belonging to their customers on backup tapes was not encrypted? <br><br><span style="font-weight: bold;">Past Breaches:</span><br>October, 2007 - <a href="http://breachblog.com/2007/10/17/losfa.aspx" target="_blank"> Iron Mountain driver does not follow company procedures</a></font><br><script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/01/18/jcp.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Fri, 18 Jan 2008 07:24:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/penney">penney</category>
      <category domain="http://securityratty.com/tag/penney customers">penney customers</category>
      <category domain="http://securityratty.com/tag/tape">tape</category>
      <category domain="http://securityratty.com/tag/backup tape">backup tape</category>
      <category domain="http://securityratty.com/tag/money">money</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/penney card immediately">penney card immediately</category>
      <category domain="http://securityratty.com/tag/information security practices">information security practices</category>
      <source url="http://breachblog.com/2008/01/18/jcp.aspx">J.C. Penney customers affected by lost GE Money backup tape</source>
    </item>
  </channel>
</rss>
