<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: petroleum]]></title>
    <link>http://securityratty.com/tag/petroleum</link>
    <description></description>
    <pubDate>Sun, 22 Jun 2008 17:58:23 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Petroleum Wholesale charged with exposing customers]]></title>
      <link>http://securityratty.com/article/1e0eee4c18853dda51b902995e1d952a</link>
      <guid>http://securityratty.com/article/1e0eee4c18853dda51b902995e1d952a</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/19/08

Organization
Petroleum Wholesale, L. P

Contractor/Consultant/Branch
None

Victims
Customers

Number Affected
Unknown

Types of Data
sensitive...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/pw.jpg" width="200" align="right" height="93"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/19/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.petroleumwholesale.com/sunmart.web/homepage.html">Petroleum Wholesale, L. P.</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>"sensitive personal information, including Social Security numbers, bank account numbers, and credit or debit card information"<br><br><span style="font-weight: bold;">Breach Description:</span><br>”HOUSTON -- Petroleum Wholesale, which operated Sunmart Travel Centers and Convenience Stores in 10 states, was charged by the Texas Attorney General of improperly disposing of customer records"<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.hcnonline.com/site/news.cfm?newsid=19788139&amp;BRD=1574&amp;PAG=461&amp;dept_id=532238&amp;rfi=6">The Pasadena Citizen</a> <br><a href="http://www.khou.com/news/local/crime/stories/khou080619_jj_storeid.1c30dcf3.html">KHOU-TV Channel 11 News</a> <br><a href="http://www.csnews.com/csn/news/article_display.jsp?vnu_content_id=1003819492">Convenience Store News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>The Pasadena Citizen<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>HOUSTON - Texas Attorney General Greg Abbott today charged Houston-based Petroleum Wholesale, L.P., which operates Sunmart Travel Centers &amp; Convenience Stores in 10 states, for exposing its customers to identity theft.<br><br>According to the state's enforcement action, Petroleum Wholesale improperly discarded customer records containing sensitive personal information, including Social Security numbers, bank account numbers, and credit or debit card information.<br><br>"This defendant is charged with failing to protect its customers' sensitive information," Attorney General Abbott said.<br><br>"With more than 20,000 Texas victims each year, identity theft remains one of the nation's fastest-growing crimes. The Office of the Attorney General will continue working to protect Texans from identity theft."<br><br>Investigators with the Office of the Attorney General (OAG) discovered that the company improperly discarded hundreds of customer records in a publicly-accessible trash container outside its former headquarters.<br><span style="font-style: italic;">[Evan] According to information posted on the Petroleum Wholesale web site, "Petroleum Wholesale services more than 350 retail locations throughout ten states."&nbsp; This breach has the potential to affect many, many people.</span><br><br>According to investigators, the records included sales receipts with customers' names and full credit or debit card numbers with expiration dates.<br><br>The records also included returned checks, along with forms listing customers' names, banking routing numbers, driver's license and Social Security numbers.<br><br>The defendant is charged with violating the 2005 Identity Theft Enforcement and Protection Act, which requires the safeguarding and proper destruction of clients' sensitive personal information.<br><br>State law establishes penalties of up to $50,000 per violation of the Act.<br><span style="font-style: italic;">[Evan] This could add up quick.&nbsp; What's a better business decision, a few hundred bucks for a cross-cut shredder and accompanying procedures, or fifty grand per incident?&nbsp; Although, I am not sure that a shredder and procedures are not all that is needed in Petroleum Wholesale's information security program (assuming one exists).</span><br><br>The OAG also charged the company with violating Chapter 35 of the Business and Commerce Code, which requires businesses to develop retention and disposal procedures for their clients' personal information.<br><br>The law provides for civil penalties of up to $500 for each abandoned record.<br><br>For more information about preventing identity theft, contact the Office of the Attorney General at (800) 252-8011 or visit the agency's Web site at <a href="http://www.texasattorneygeneral.gov.<br><br><span">www.texasattorneygeneral.gov.<br><br><span</a> style="font-weight: bold;">Commentary:</span><br>One question that isn't clear from the news reports is whether or not this was a common practice at Petroleum Wholesale.&nbsp; Organizations should take heed of this case.&nbsp; I think actions taken by Mr. Abbott and other State Attorney Generals will only become more frequent.<br><br>I look forward to more information in the future about this case. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/22/pw.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Sun, 22 Jun 2008 17:58:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/petroleum wholesale">petroleum wholesale</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/company improperly">company improperly</category>
      <category domain="http://securityratty.com/tag/improperly">improperly</category>
      <category domain="http://securityratty.com/tag/debit card information">debit card information</category>
      <category domain="http://securityratty.com/tag/debit card">debit card</category>
      <source url="http://breachblog.com/2008/06/22/pw.aspx">Petroleum Wholesale charged with exposing customers</source>
    </item>
  </channel>
</rss>
