In 2007, when Johns Hopkins learned that backup tapes had been lost in transit, I complimented them for their handling of the incident. They’ve managed to impress me yet again — which is no small feat — by their handling of a recent incident…. In February, this site posted a story about a breach that…
Category: Breach Incidents
Branch Banking & Trust employee arrested for selling client information
On January 14, law enforcement officials investigating another matter discovered client information from Branch Banking & Trust Co. (BB&T) in the possession of unauthorized individuals. Once alerted to the breach, BB&T conducted an internal investigation and discovered that a former employee who had legitimate access to client accounts had abused the access and had sold…
A few more breaches that didn’t make the news
Thanks to those states who post notifications online…. TravelCLICK, Inc. reported (pdf) that customers who used their web site to book hotel reservations may have had their data accessed by unauthorized others during the period February to March of this year. Reservation data included names, full credit card numbers, expiration date, but no CVV or…
FTC enforcement of data protection
Since 2001, the FTC has filed charges against 25 businesses for failure to protect consumers’ information. The cases were cited in their May 5th testimony and comments (pdf) in Congress about two bills being considered: H.R. 2221, the Data Accountability and Protection Act, and H.R. 1319, the Informed P2P User Act. The cases fall into…
UK: Baby records theft sparks inquiry
From the BBC: An inquiry is under way after the records of babies born in Aberdeen Maternity Hospital were handed in after apparently being stolen. Letters of apology have been sent to 175 parents after the records of their babies born between 2001 and 2008 were given to NHS Grampian. The documents appeared to have…
Deja vu all over again: Another Continental Airlines laptop stolen
Continental Airlines, which reported a laptop stolen from their Newark office earlier this year found themselves again in the unenviable position of notifying employees of yet a second stolen laptop. On March 30, a laptop was stolen that contained employee information such as name, Social Security number, Continental ID number, position title, and contact address….