DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

What should the headline on the Epsilon breach be?

Posted on April 5, 2011 by Dissent

By now, there have been thousands of news stories on the security breach at Epsilon, a Dallas-based  email marketing service provider.  Many of the headlines have incorporated the names of some of the firm’s biggest clients like Chase, Target, or Kroger.  Many of the headlines have seemingly tried to frighten consumers into reading the story by asking, “Has your email been stolen?”   Others have tried to alert consumers to expect more spam – or more importantly from a security perspective – to be alert to phishing attempts.

People have been posting that they’ve received 5, 6, 10,  or even 20 notifications as a result of the breach, but what’s the real story here?    I look forward to reading the analyses of the security professionals, but as a consumer and privacy advocate, I’ve been mulling over how I see the Epsilon breach’s significance.  Here’s how I see what should have been the  bigger headlines for this incident:

“Who the heck is Epsilon and why do they have my data?”

One thing that should become obvious even to those in Congress who have lived under a business-hugging rock is that most consumers really have no idea who is in possession of our information. We don’t knowingly grant a specific firm permission to retain or use our data, and we would have no idea what company to approach directly if we had any question about our data.  Allowing consumers the right to correct or ask for deletion of data needs to be accompanied by a clear statement as to who has our data.

“Companies have no legal obligation to report a data breach”

Given our crazy patchwork of breach notification laws in the U.S., companies here may have had no obligation to notify customers.  Indeed, I can think of no state, offhand, that requires breach notification for “just” a name and email address, can you?

Should there be a required notification for name plus email address?  I can already anticipate the objections, based on cost and risk that  over-notification will allegedly result in consumers ignoring notifications.  But if you do think that such breaches should result in notification because of the risk of spear-phishing, how do you reconcile that with the fact that the education sector considers names + email addresses  “directory information” that they can  publish  or disseminate without breaching federal privacy laws?

The U.S. has failed, until now, to come up with an agreed-upon definition of  “personally identifiable information” and “sensitive personally identifiable information.”  That lack of a uniform federal definition puts us way behind Europe where definitions have been long-established.

“I unsubscribed, so why did they still have my data?”

Some consumers complained on Twitter that they were angered to get a notification because they had terminated any relationship with the company years earlier.  In some cases, like the consumer who was surprised to get a notice from Red Roof Inn although he had not stayed with them since 2003, the notice reminds us that data lives on forever unless we explicitly demand its deletion from current and backup files – or until Congress imposes some regulations requiring automatic deletion of data after a certain period of time.

“Who’s minding the store on security for outsourced data?”

The issue of securing outsourced data is an old one, but if the Epsilon breach teaches anything, it will hopefully teach businesses that they need to pay even more attention to the security at the their vendors.   There were attacks on email service providers in 2009 and 2010.  The ones in 2010 got a bit more media attention and Brian Krebs did a great job of trying to expose the concern, but here we are six months later and there’s another huge breach.  A Walgreens spokesperson who responded to an inquiry I sent as to why they had had a second breach of their customers’ data in recent months wrote, “After the incident last year, Walgreens requested that Epsilon put a number additional security measures in place. Apparently, that expectation was not fully met.”

Walgreens asked for additional security.  Did they actually follow up to ensure that any changes Epsilon made were adequate or did they just accept assurances?   I don’t know, but it doesn’t matter whether you’re in the business sector or the health care sector – business associates and vendors are responsible for a significant percentage of data breaches and it seems apparent to this humble consumer that entities need to investigate and audit the security of their vendors as seriously as they audit and monitor the security of data they retain on their own servers.

Epsilon has much more data than just names and email addresses. It has a wealth of information that it data mines on consumers.  The fact that those data were not acquired or stolen – this time – is a matter of dumb luck for consumers.  But it is also  a matter of dumb security –  weren’t the data encrypted? If not, why not?

So… what do you think the headline should have been for the Epsilon breach?

Related:  List of companies affected.

Category: Breach IncidentsHack

Post navigation

← UK: Council printer mix up breached data protection laws
Nurse allowed to resign in medical chart snooping case →

1 thought on “What should the headline on the Epsilon breach be?”

  1. Aaron says:
    April 6, 2011 at 9:54 am

    “Large Companies Complicit in Epsilon’s Breach”
    Big business has abdicated the responsibility of information security to lowest-cost, third-party suppliers knowing that consumers and press will not hold them accountable for data loss. Consumers are totally justified in opting out of all e-marketing, and in many cases just taking their business elsewhere. Should we believe Epsilon has sole responsibility for our data and totally excuse the companies that trusted them with it?

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Ransomware Attack on ADP Partner Exposes Broadcom Employee Data
  • Anne Arundel ransomware attack compromised confidential health data, county says
  • Australian national known as “DR32” sentenced in U.S. federal court
  • Alabama Man Sentenced to 14 Months in Connection with Securities and Exchange Commission X Hack that Spiked Bitcoin Prices
  • Japan enacts new Active Cyberdefense Law allowing for offensive cyber operations
  • Breachforums Boss “Pompompurin” to Pay $700k in Healthcare Breach
  • HHS Office for Civil Rights Settles HIPAA Cybersecurity Investigation with Vision Upright MRI
  • Additional 12 Defendants Charged in RICO Conspiracy for over $263 Million Cryptocurrency Thefts, Money Laundering, Home Break-Ins
  • RIBridges firewall worked. But forensic report says hundreds of alarms went unnoticed by Deloitte.
  • Chinese Hackers Hit Drone Sector in Supply Chain Attacks

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law
  • Montana Becomes First State to Close the Law Enforcement Data Broker Loophole
  • Privacy enforcement under Andrew Ferguson’s FTC
  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law
  • CFPB Quietly Kills Rule to Shield Americans From Data Brokers
  • South Korea fines Temu for data protection violations
  • The BR Privacy & Security Download: May 2025

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.