DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Some days, I pull my hair out, Thursday edition

Posted on October 6, 2011 by Dissent

Everywhere I look, there are data breaches that I would want to include in DataLossDB.org’s database.  But as I backfill the database to include incidents reported on my blogs that were never in the database, my research stumbles over  tons of other breaches that should also be included.  Rather than getting closer and closer to finishing the backfilling task, it’s gotten huger and huger – so much so that I am beginning to think about changing my pseudonym to Sisyphus.

Complicating the task is the fact that we still have a lot of  newly revealed breaches that occurred in past years where we have insufficient information to create a reasonable entry in the database.  Consider this excerpt from a press release yesterday about Dionne Witherspoon’s sentencing:

According to information submitted to the court by Assistant U.S. Attorney Sherri L. Schornstein, Witherspoon helped organize a highly sophisticated identity theft and fraud ring from December 2006 through March 2010 that included more than 176 corporate and individual victims and at least 765 transactions resulting in approximately $1,446,805 in fraudulently obtained lines of credit and charges to those lines of credit of approximately $88,855.

Witherspoon put together an extensive network of co-conspirators who obtained victims’ identifying information and bank account information by stealing mail from the mailboxes at personal residences located in the District of Columbia and elsewhere.

The network also stole credit card receipts from a medical office in the 7300 block of Wisconsin Avenue NW and from two locations of Johnson’s Flower Shop, at 4200 Wisconsin Ave. NW, Washington, D.C. and 10313 Kensington Ave., Kensington, Md. In addition, credit card receipts and prescriptions were stolen from the CVS Pharmacy at 13th and U Streets NW, and student identifying information was stolen from Howard University.

Whose medical office? Did we know about this before? Did the patients know about this? And what about Johnson’s Flower Shop? That breach was never in the media as far as I can find. Were those customers notified and if so, by whom, and when? And were the Howard University data from a stolen laptop incident we knew about or from some low-tech theft of paper records? And what about the CVS receipts? Did CVS know and report this to HHS/OCR and the patients?

This press release reveals four incidents that should be in the database (or five if you count the two flower shop stores as separate incidents). Four incidents associated with ID theft that we did not know about. That’s four too many, for my money.

There really needs to be a revision in the way breaches are handled so that the public is assured that they will be notified of breaches involved in criminal investigations and that we are provided with sufficient details about these incidents so that we can learn from them. Otherwise, I fear that too many security analyses will continue to focus on high-tech breaches while ignoring the low-tech paper theft incidents that lead to ID theft and fraud.

In the meantime, I’m going to grab more coffee and add a note to myself to add these frustratingly incomplete entries in the database.

Category: Breach IncidentsBusiness SectorCommentaries and AnalysesEducation SectorHealth DataID TheftPaperTheftU.S.

Post navigation

← UK: Details of 'care-in-the-home' patients found in car park
IU addresses information breach at School of Optometry →

4 thoughts on “Some days, I pull my hair out, Thursday edition”

  1. Bart Porter says:
    October 6, 2011 at 1:19 pm

    I can relate. Gathering data security news is a complicated chore, but you can take solace in the knowledge that you are educating a lot of people and performing a good job.

  2. golde1 says:
    October 19, 2011 at 9:02 pm

    amen!!! This is why we need a single database as a requirement of the new legislation – without any safe harbors.

  3. golde1 says:
    October 19, 2011 at 9:06 pm

    what most people don’t know is you do this for free and after working a full time job. Dissent should receive many kudos and if you can contribute to this effort you should. Too many people use the info from this listing for free to make their own lists which then get publicity. At least list the resource- THIS ONE- where you got the info. It is easy to just lift data and plop it into your own list. Give credit where credit is due.

    1 million Shout OUTs for the person who takes so much time to educate us all. Thank you dissent,

    1. admin says:
      October 20, 2011 at 8:13 am

      Thanks so much for the kind words. I know there are many companies who use the data I compile – whether here or for DLDB – to promote their services or agenda. Those companies or non-profits should actively and financially support DLDB. If they throw money at this site, they can’t get a tax deduction, and I don’t accept donations anyway, but donations to DataLossDB are probably deductible for them.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Data breach of patient info ends in firing of Miami hospital employee
  • Texas DOT investigates breach of crash report records, sends notification letters
  • PowerSchool hacker pleads guilty, released on personal recognizance bond
  • Rewards for Justice offers $10M reward for info on RedLine developer or RedLine’s use by foreign governments
  • New evidence links long-running hacking group to Indian government
  • Zaporizhzhia Cyber ​​Police Exposes Hacker Who Caused Millions in Losses to Victims by Mining Cryptocurrency
  • Germany fines Vodafone $51 million for privacy, security breaches
  • Google: Hackers target Salesforce accounts in data extortion attacks
  • The US Grid Attack Looming on the Horizon
  • US govt login portal could be one cyberattack away from collapse, say auditors

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • California county accused of using drones to spy on residents
  • How the FBI Sought a Warrant to Search Instagram of Columbia Student Protesters
  • Germany fines Vodafone $51 million for privacy, security breaches
  • Malaysia enacts data sharing rules for public sector
  • U.S. Enacts Take It Down Act
  • 23andMe Bankruptcy Judge Ponders Trump Bill’s Injunction Impact
  • Hell No: The ODNI Wants to Make it Easier for the Government to Buy Your Data Without Warrant

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.