<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: saks]]></title>
    <link>http://securityratty.com/tag/saks</link>
    <description></description>
    <pubDate>Sun, 11 May 2008 17:28:38 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Two stolen Saks Incorporated laptops contained sensitive information]]></title>
      <link>http://securityratty.com/article/93d97ba2583b32143ad38008c44b1d57</link>
      <guid>http://securityratty.com/article/93d97ba2583b32143ad38008c44b1d57</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
4/30/08

Organization
Saks Incorporated

Contractor/Consultant/Branch
None

Victims
Customers

Number Affected
Unknown

According to the New Hampshire...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/saks.jpg" align="right" height="75" width="75"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>4/30/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.saksincorporated.com/">Saks Incorporated</a><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown*<br><br><font size="1">*According to the New Hampshire State Attorney General breach notification there were 163 persons affected who reside in the state of New Hampshire<br></font><br><span style="font-weight: bold;">Types of Data:</span><br>Name, address, Saks Fifth Avenue credit card account number, and/or Saks Fifth Avenue/MasterCard co-branded credit card account number.<br><br><span style="font-weight: bold;">Breach Description:</span><br>"In mid-April 2008, Saks learned that four company laptops were stolen.&nbsp; Two of the stolen laptops contained several files that included customer names, addresses, Saks Fifth Avenue credit card account numbers, and/or Saks Fifth Avenue/MasterCard co-branded credit card account numbers."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://doj.nh.gov/consumer/pdf/saks.pdf">New Hampshire State Attorney General breach notification</a><br><br><span style="font-weight: bold;">Report Credit:</span><br>The New Hampshire State Attorney General<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>In mid-April 2008, Saks learned that four company laptops were stolen.&nbsp; Two of the stolen laptops contained several files that included customer names, addresses, Saks Fifth Avenue credit card account numbers, and/or Saks Fifth Avenue/MasterCard co-branded credit card account numbers.<br><br>Based on our investigation, we have confirmed that these files did not include Social Security numbers, the credit cards' expiration dates, pin numbers, codes, or passwords, or any other types of sensitive data.<br><span style="font-style: italic;">[Evan] Thank God for that!</span><br><br>Given the very limited type of personal information on these files and that it was stored on password-protected laptops, we believe there is a very low risk of identity theft or credit card fraud as a result of this event.<br><span style="font-style: italic;">[Evan] I agree with the limited type of information argument, but could care less about password-protected laptops.&nbsp; Password-protected laptops are little more than nothing to stop someone for accessing the information.</span><br style="font-style: italic;"><br>We have no indication that this personal information has been accessed or misused, or even that the laptops are in the hands of someone seeking to misuse the information.<br><br>Nor was this a breach of our network, website, or database (as is typical in many company breaches covered by the news).<br><span style="font-style: italic;">[Evan] I think laptop thefts and losses are more typical that network, website or database breaches.</span><br><br>The company has drafted a written notice of the breach that it will be sending to the affected individuals imminently.<br><br>Saks takes its customers' privacy very seriously, and we have exercised utmost caution and diligence in our response following the discovery of the theft.<br><br>Within hours of learning of the theft, we initiated our own investigation into the incident and notified law enforcement.<br><br>Finally, if you have additional questions related to this situation, you can contact us between the hours of 9:00 a.m. ET through 6:00 p.m. ET on Monday though Saturday through our dedicated toll-free information helpline at 1-888-724-2455.<br><br>We deeply regret any inconvenience or concern that this matter may cause you.<br><br><span style="font-weight: bold;">Commentary:</span><br>The letter sent to the affected individuals is signed by Stephen I. Sadove, Chairman and Chief Executive Office of Saks Incorporated.&nbsp; I respect Mr. Sadove for addressing this situation in person (so to speak).&nbsp; It demonstrates his understanding that information security is a corporate issue for which he is ultimately responsible. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/05/11/saks.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Sun, 11 May 2008 17:28:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/saks">saks</category>
      <category domain="http://securityratty.com/tag/laptops">laptops</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/andor saks">andor saks</category>
      <category domain="http://securityratty.com/tag/company laptops">company laptops</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/breach description">breach description</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/credit card account">credit card account</category>
      <source url="http://breachblog.com/2008/05/11/saks.aspx">Two stolen Saks Incorporated laptops contained sensitive information</source>
    </item>
  </channel>
</rss>
