I think it would be fair to say that Kierkegaard & Perry Labs, Inc’s breach notification to Maryland in July impressed me somewhat unfavorably. KPL was reporting a hack that had compromised some customers’ names, addresses, and credit card numbers with expiration dates and CVV codes. Their investigation revealed that 8 customers’ information was acquired (not…
Category: Business Sector
ADP coding error also impacted AlliedBarton Security Services, too
I’m still uncovering details of the ADP coding error breach that impacted employees of the City of Houston, US Airways, and McKesson. Now we can add AlliedBarton Security Services to the list of affected clients. And Lennox International. Interestingly, these newly posted reports indicate that 206 of ADP’s clients were affected by this breach. In…
Clark & Anderson accounting firm notifies thousands after unencrypted backup drive stolen from employee’s car
A Maryland accounting firm had to notify 2,906 Maryland residents after an unencrypted backup drive was stolen from an employee’s car at his home. The theft occurred on August 4, but Clark & Anderson, P.A. didn’t learn of it until August 8. In a letter dated August 30 to the Maryland Attorney General’s Office, they…
State Farm call center worker misused customers’ credit card information
Two days after a State Farm auto insurance customer made a payment on their insurance policy over the phone, the customer called State Farm back to report that their credit card information had been misused. State Farm investigated, and one month later, on September 4, the insurer notified the Maryland Attorney General’s Office that they…
Errors by both Sentry Life Insurance and the Department of Labor expose 401k participants’ information online
Sentry Life Insurance is a service provider for many companies’ 401k plans. In that capacity, they assist clients in the preparation of, and submission of, the plans’ Form 5500 to the Department of Labor. On July 2, Sentry discovered that some plans’ Form 5500 submissions to DOL contained an attachment with the individuals’ names, Social Security numbers,…
One year after data theft, Primedia (RentPath) employees and applicants notified of breach
I could have sworn I had posted something about the Primedia (formerly RentPath) breach, but maybe I just tweeted it and forgot to blog it. Thankfully, Jeff Goldman of eSecurity Planet provided a preliminary media report in June. This blog post incorporates an update to the incident. Back in May, attorneys for Primedia notified at…