DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Some days, I pull my hair out, Thursday edition

Posted on October 6, 2011 by Dissent

Everywhere I look, there are data breaches that I would want to include in DataLossDB.org’s database.  But as I backfill the database to include incidents reported on my blogs that were never in the database, my research stumbles over  tons of other breaches that should also be included.  Rather than getting closer and closer to finishing the backfilling task, it’s gotten huger and huger – so much so that I am beginning to think about changing my pseudonym to Sisyphus.

Complicating the task is the fact that we still have a lot of  newly revealed breaches that occurred in past years where we have insufficient information to create a reasonable entry in the database.  Consider this excerpt from a press release yesterday about Dionne Witherspoon’s sentencing:

According to information submitted to the court by Assistant U.S. Attorney Sherri L. Schornstein, Witherspoon helped organize a highly sophisticated identity theft and fraud ring from December 2006 through March 2010 that included more than 176 corporate and individual victims and at least 765 transactions resulting in approximately $1,446,805 in fraudulently obtained lines of credit and charges to those lines of credit of approximately $88,855.

Witherspoon put together an extensive network of co-conspirators who obtained victims’ identifying information and bank account information by stealing mail from the mailboxes at personal residences located in the District of Columbia and elsewhere.

The network also stole credit card receipts from a medical office in the 7300 block of Wisconsin Avenue NW and from two locations of Johnson’s Flower Shop, at 4200 Wisconsin Ave. NW, Washington, D.C. and 10313 Kensington Ave., Kensington, Md. In addition, credit card receipts and prescriptions were stolen from the CVS Pharmacy at 13th and U Streets NW, and student identifying information was stolen from Howard University.

Whose medical office? Did we know about this before? Did the patients know about this? And what about Johnson’s Flower Shop? That breach was never in the media as far as I can find. Were those customers notified and if so, by whom, and when? And were the Howard University data from a stolen laptop incident we knew about or from some low-tech theft of paper records? And what about the CVS receipts? Did CVS know and report this to HHS/OCR and the patients?

This press release reveals four incidents that should be in the database (or five if you count the two flower shop stores as separate incidents). Four incidents associated with ID theft that we did not know about. That’s four too many, for my money.

There really needs to be a revision in the way breaches are handled so that the public is assured that they will be notified of breaches involved in criminal investigations and that we are provided with sufficient details about these incidents so that we can learn from them. Otherwise, I fear that too many security analyses will continue to focus on high-tech breaches while ignoring the low-tech paper theft incidents that lead to ID theft and fraud.

In the meantime, I’m going to grab more coffee and add a note to myself to add these frustratingly incomplete entries in the database.


Related:

  • Two U.K. teenagers appear in court over Transport of London cyber attack
  • ModMed revealed they were victims of a cyberattack in July. Then some data showed up for sale.
  • Toys “R” Us Canada customers notified of breach of personal information
  • Gatineau gymnastics centre warns members of possible data breach
  • Confidence in ransomware recovery is high but actual success rates remain low
  • Protected health information of 462,000 members of Blue Cross Blue Shield of Montana involved in Conduent data breach
Category: Breach IncidentsBusiness SectorCommentaries and AnalysesEducation SectorHealth DataID TheftPaperTheftU.S.

Post navigation

← UK: Details of 'care-in-the-home' patients found in car park
IU addresses information breach at School of Optometry →

4 thoughts on “Some days, I pull my hair out, Thursday edition”

  1. Bart Porter says:
    October 6, 2011 at 1:19 pm

    I can relate. Gathering data security news is a complicated chore, but you can take solace in the knowledge that you are educating a lot of people and performing a good job.

  2. golde1 says:
    October 19, 2011 at 9:02 pm

    amen!!! This is why we need a single database as a requirement of the new legislation – without any safe harbors.

  3. golde1 says:
    October 19, 2011 at 9:06 pm

    what most people don’t know is you do this for free and after working a full time job. Dissent should receive many kudos and if you can contribute to this effort you should. Too many people use the info from this listing for free to make their own lists which then get publicity. At least list the resource- THIS ONE- where you got the info. It is easy to just lift data and plop it into your own list. Give credit where credit is due.

    1 million Shout OUTs for the person who takes so much time to educate us all. Thank you dissent,

    1. admin says:
      October 20, 2011 at 8:13 am

      Thanks so much for the kind words. I know there are many companies who use the data I compile – whether here or for DLDB – to promote their services or agenda. Those companies or non-profits should actively and financially support DLDB. If they throw money at this site, they can’t get a tax deduction, and I don’t accept donations anyway, but donations to DataLossDB are probably deductible for them.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says
  • The Case for Making EdTech Companies Liable Under FERPA
  • NHS providers reviewing stolen Synnovis data published by cyber criminals

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation
  • Who’s watching the watchers? This Mozilla fellow, and her Surveillance Watch map

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.