DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Andy Frain Services reports stolen laptop, but were they also hacked?

Posted on September 6, 2019 by Dissent

Andy Frain Services has reported a breach to the California Attorney General’s Office. The breach reportedly occurred on May 2, and their letter to those affected begins:

We are writing with important information regarding a recent security incident. The privacy and security of the personal information we maintain is of the utmost importance to Andy Frain Services, Inc. (“Andy Frain Services”). As such, we wanted to provide you with information about the incident, explain the services we are making available to you, and let you know that we continue to take significant measures to protect your information.

So what happened? If they take “significant measures,” I might expect to see some unusual or sophisticated attack, but no. It seems that an employee’s laptop with unencrypted names and Social Security numbers was stolen from her car. Not surprisingly, the laptop was (only) password-protected. template. Their notification did not indicate how many individuals had their names and SSN on the stolen device or whether the employee violated any policies. Nor does it indicate whether there was any disciplinary actions taken with respect to the employee.

You can read the template of their full notification letter here. It includes an offer of one year of complimentary services with an Experian product. Those affected can call a phone line set up to handle inquiries about the incident and steps that can be taken to protect themselves.

Not knowing anything about Andy Frain Services, I googled the firm and learned that they provide integrated security services for events. They have more than a dozen locations in the U.S., as well as locations in China, England, and Canada.

But it was the google search results that surprised me the most. Under the link to their web site was Google’s warning, “This site may be hacked.”
Google result for Andy Frain Services has a caution from Google saying "This site may be hacked."

DataBreaches.net emailed Andy Frain Services on September 4 through their web site to ask them if they were aware of the Google warning that they might have been hacked and whether there was any connection between that message and the laptop theft breach they had reported to California. No answer was received and the firm did not respond immediately to a voicemail left for them tonight. If a response is received, this post may be updated.

Category: Breach IncidentsCommentaries and AnalysesTheft

Post navigation

← UK: Gender identity clinic leaks almost 2,000 patients’ email addresses
Meridian Community College discloses a breach that was discovered in January →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes
  • Cocospy stalkerware apps go offline after data breach
  • Ex-NSA bad-guy hunter listened to Scattered Spider’s fake help-desk calls: ‘Those guys are good’
  • Former Sussex Police officer facing trial for rape charged with 18 further offences relating to computer misuse
  • Beach mansion, Benz and Bitcoin worth $4.5m seized from League of Legends hacker Shane Stephen Duffy
  • Fresno County fell victim to $1.6M phishing scam in 2020. One suspected has been arrested, another has been indicted.
  • Ransomware Attack on ADP Partner Exposes Broadcom Employee Data
  • Anne Arundel ransomware attack compromised confidential health data, county says
  • Australian national known as “DR32” sentenced in U.S. federal court
  • Alabama Man Sentenced to 14 Months in Connection with Securities and Exchange Commission X Hack that Spiked Bitcoin Prices

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Police secretly monitored New Orleans with facial recognition cameras
  • Cocospy stalkerware apps go offline after data breach
  • Drugmaker Regeneron to acquire 23andMe out of bankruptcy
  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law
  • Montana Becomes First State to Close the Law Enforcement Data Broker Loophole
  • Privacy enforcement under Andrew Ferguson’s FTC
  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.