DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Andy Frain Services reports stolen laptop, but were they also hacked?

Posted on September 6, 2019 by Dissent

Andy Frain Services has reported a breach to the California Attorney General’s Office. The breach reportedly occurred on May 2, and their letter to those affected begins:

We are writing with important information regarding a recent security incident. The privacy and security of the personal information we maintain is of the utmost importance to Andy Frain Services, Inc. (“Andy Frain Services”). As such, we wanted to provide you with information about the incident, explain the services we are making available to you, and let you know that we continue to take significant measures to protect your information.

So what happened? If they take “significant measures,” I might expect to see some unusual or sophisticated attack, but no. It seems that an employee’s laptop with unencrypted names and Social Security numbers was stolen from her car. Not surprisingly, the laptop was (only) password-protected. template. Their notification did not indicate how many individuals had their names and SSN on the stolen device or whether the employee violated any policies. Nor does it indicate whether there was any disciplinary actions taken with respect to the employee.

You can read the template of their full notification letter here. It includes an offer of one year of complimentary services with an Experian product. Those affected can call a phone line set up to handle inquiries about the incident and steps that can be taken to protect themselves.

Not knowing anything about Andy Frain Services, I googled the firm and learned that they provide integrated security services for events. They have more than a dozen locations in the U.S., as well as locations in China, England, and Canada.

But it was the google search results that surprised me the most. Under the link to their web site was Google’s warning, “This site may be hacked.”
Google result for Andy Frain Services has a caution from Google saying "This site may be hacked."

DataBreaches.net emailed Andy Frain Services on September 4 through their web site to ask them if they were aware of the Google warning that they might have been hacked and whether there was any connection between that message and the laptop theft breach they had reported to California. No answer was received and the firm did not respond immediately to a voicemail left for them tonight. If a response is received, this post may be updated.

Category: Breach IncidentsCommentaries and AnalysesTheft

Post navigation

← UK: Gender identity clinic leaks almost 2,000 patients’ email addresses
Meridian Community College discloses a breach that was discovered in January →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
  • PowerSchool paid a hacker’s extortion demand, but now school district clients are being extorted anyway (3)
  • Defending Against UNC3944: Cybercrime Hardening Guidance from the Frontlines
  • Call for Public Input: Essential Cybersecurity Protections for K-12 Schools (2025-26 SY)
  • Cyberattack puts healthcare on hold for hundreds in St. Louis metro
  • Europol: DDoS-for-hire empire brought down: Poland arrests 4 administrators, US seizes 9 domains

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim
  • Privacy matters to Canadians – Privacy Commissioner of Canada marks Privacy Awareness Week with release of latest survey results
  • Missouri Clinic Must Give State AG Minor Trans Care Information
  • Georgia hospital defeats data-tracking lawsuit
  • No Postal Service Data Sharing to Deport Immigrants
  • DOGE aims to pool federal data, putting personal information at risk
  • Privacy concerns swirl around HHS plan to build Medicare, Medicaid database on autism

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.
Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report