Home > Security News > Data theft affects 88 million-plus Americans
Security News:
EMAIL THIS

Data theft affects 88 million-plus Americans

By Bill Brenner, Senior News Writer
21 Jun 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

The steady stream of data breaches that started with ChoicePoint Inc. in February 2005 has left more than 88 million Americans at risk for identity fraud, according to a list tallied by the Privacy Rights Clearinghouse (PRC).

The latest incidents, which have not yet made it onto the PRC's list, involve Foster City, Calif.-based Visa USA Inc. and Atlanta, Ga.-based Equifax Inc.

Tuesday both companies acknowledged security breaches. Visa said that an ATM security breakdown may have exposed data on an undisclosed number of customers. The breach dates back to February, when Visa began notifying banks of a security issue affecting a contractor that processes ATM transactions, according to published reports. Visa publicly acknowledged the breach after Charlotte, N.C.-based Wachovia Bank N.A. decided to replace an untold number of debit cards issued to its customers, prompting a wave of media inquiries.

Separately, Equifax -- one of the three major U.S. credit reporting bureaus -- acknowledged that a laptop computer containing employee names and Social Security numbers was stolen from a worker traveling on a train near London. Company spokesman David Rubinger told the Reuters news agency that the May 29 theft affects nearly all of the company's 2,500 U.S. employees, aside from those hired in roughly the last two months. Personal data belonging to millions of consumers who obtain credit scores from Equifax was not compromised, Rubinger said, adding that it would be difficult for would-be thieves to decipher the data or determine that it included Social Security numbers in the first place. The employee responsible for the laptop was disciplined, but Rubinger wouldn't describe the punishment or release the employee's name.

The rate of data breaches has intensified since mid-May, when the U.S. Department of Veterans Affairs (VA) confirmed that records for every veteran discharged from the military since 1975 were stolen from the home of an agency employee. The VA later revealed that the breach also put active duty personnel at risk for identity fraud.

According to the list on the PRC Web site, the most recent security breaches involve:

  • The New York State Controller's Office, which acknowledged that a data cartridge containing payroll data of employees who work for a variety of state agencies was lost during shipment. The data included the names, salaries, Social Security numbers and home addresses of about 1,300 people.

  • Union Pacific, which acknowledged the theft of an employee's laptop containing the names, birth dates and Social Security numbers of 30,000 former employees.

  • American Insurance Group (AIG), which acknowledged the theft of a computer server containing personal information such as names, Social Security numbers and tens of thousands of medical records on 930,000 people.

  • Western Illinois University, where a hacker compromised a university server that contained names, addresses, credit card numbers and Social Security numbers of 240,000 people.

  • The U.S. Dept of Energy's Hanford Nuclear Reservation, where police believe personal data on 4,000 current and former workers was compromised. Police found a 1996 list with workers' names and other information in a home during an unrelated investigation, leading to suspicion that the facility suffered a security breach.

    Tags: Identity Theft and Data Security BreachesInformation Security Laws, Investigations and EthicsSecurity Industry Market Trends, Predictions and ForecastsVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Identity Theft and Data Security Breaches
    Chip and PIN adoption serves lesson for U.S. payment industry
    Group to shed light on secure identity management threats
    Heartland CIO is critical of First Data's credit card tokenization plan
    Heartland CIO on end-to-end encryption, credit card tokenization
    Heartland CIO on PCI, E3 project
    Visa probes tokens, encryption for PCI card data protection
    University data breach exposes 163,000 women to identity theft
    TJX thrives following breach, bucks sour economy
    Security expert's PCI analysis misguided, says PCI Council GM
    External attacks start with unintentional mistakes, survey finds

    Information Security Laws, Investigations and Ethics
    Melissa Hathaway urges more cooperation, government attention to cybersecurity
    Cybersecurity czar candidate questions clout of new position
    DHS fills National Cybersecurity Center post
    FTC shutters rogue ISP for hosting malicious content, botnets
    Experts optimistic of Obama cybersecurity plan
    WH cybersecurity plan needs private sector guidance
    Obama announces creation of cybersecurity coordinator position
    Cybersecurity Act of 2009: Power grab, or necessary step?
    Face-off: Who should be in charge of cybersecurity?
    Feds should get private sector advice on cybersecurity

    Security Industry Market Trends, Predictions and Forecasts
    M86 buys Web security gateway vendor Finjan
    Information Security Decisions 2009: Presentation downloads
    Bruce Schneier on outsourcing, awareness training
    Marcus Ranum on cyberwarfare, infosec careers
    McAfee survey finds faults in midmarket enterprise security
    Email archiving vendor sues Gartner over Magic Quadrant
    Information Security magazine October issue PDF
    Editor's Desk: Security 7 Winners Chronicle Trends That Shape The Industry
    Information Security magazine Security 7 Award winners
    Security Squad: Privacy gone awry
    Security Industry Market Trends, Predictions and Forecasts Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    bot worm  (SearchSecurity.com)
    CISP-PCI  (SearchFinancialSecurity.com)
    cookie poisoning  (SearchSecurity.com)
    drive-by pharming  (SearchSecurity.com)
    extrusion prevention  (SearchSecurity.com)
    identity theft  (SearchSecurity.com)
    parameter tampering  (SearchSecurity.com)
    pretexting  (SearchCIO.com)
    Rock Phish  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts