Home > Security News > VA desktop PC stolen, 36,000 could be at risk
Security News:
EMAIL THIS

VA desktop PC stolen, 36,000 could be at risk

By Dennis Fisher, News Director
07 Aug 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Update: For the second time in less than three months, a computer with the personal information of thousands of U.S. veterans has been stolen. The Department of Veterans Affairs said Monday that a desktop PC containing data on as many as 16,000 veterans was stolen from the office of Unisys Corp., a contractor that was doing insurance collections for the VA.

In a statement, the VA said it believes the PC contains data on about 5,000 patients who received care at a Philadelphia medical center, and about 11,000 who were treated at a facility in Pittsburgh. The VA is investigating the possibility that the machine also has data on another 20,0000 patients from its Pittsburgh facility. The data on the PC is believed to include Social Security numbers, names, addresses, dates of birth, insurance information, dates of military service and medical claim information.

The Unisys theft comes on the heels of a widely publicized incident in May involving the theft of a VA laptop and external hard containing personally identifiable information on 26.5 million veterans and active-duty military personnel. The VA laptop was found about a month later and law enforcement officials believe that none of the sensitive data was even accessed by the thief. However, the VA's handling of the incident and slow response led to an internal investigation that resulted in a scathing report from the department's Office of the Inspector General last month.

VA officials learned of this new theft on Aug. 3 and sent a team of investigators to the Unisys office in Reston, Va., just outside Washington, D.C., to help in the search for the PC.

"VA's Inspector General, the FBI and local law enforcement are conducting a thorough investigation of this matter," R. James Nicholson, secretary of the VA, said in a statement. "VA is making progress to reform its information technology and cybersecurity procedures, but this report of a missing computer at a subcontractor's secure building underscores the complexity of the work ahead as we establish VA as a leader in data and information security."

The latest VA incident has raised the ire of a number of Congressmen, many of whom are working to pass data-breach bills.

"I am angered and outraged that while our veterans protect our nation's security, our nation is unable to protect their personal information," Rep. Frank LoBiondo (R-N.J.) said in a statement. "Twice in three months our veterans' personal information is found in peril. Decisive action must be taken now to install the necessary security protocols and prevent future breaches."

Security experts say that the VA thefts and similar incidents at other government agencies and private sector organizations are symptoms of a systematic problem: too much trust.

"The bigger an organization gets, the more at risk it is to insiders," said Brian Contos, chief security officer at ArcSight Inc., in Cupertino, Calif. "The more people there are with access, either physical or logical, the more opportunities there are" for malfeasance.

In the case of the most recent VA theft, the computer was taken from a secure facility owned by Unisys, a subcontractor two steps removed from the agency itself. Contos said that government agencies in general have been making strides in dealing with security issues, but the VA incidents show that many of them still are not paying attention to the right areas and asking the hard questions.

"Why is so much sensitive data being stored on things like laptops and PCs that can be carried out the door? You have to have real policies that have teeth and enforce them," Contos said. "The hardest thing to do is manage assets. You don't need an uberhacker to plug in an iPod and download tons of data."

Tags: Identity Theft and Data Security BreachesInformation Security Laws, Investigations and EthicsVulnerability Risk AssessmentEnterprise Data GovernanceEnterprise Risk Management: Metrics and AssessmentsInformation Security Policies, Procedures and GuidelinesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Identity Theft and Data Security Breaches
TJX to pay $9.75 million for data breach investigations
Man pleads guilty in online banking hacking scam
White House cybersecurity czar faces major hurdles
Heartland breach cost $12.6 million, CEO says
An inside look at security log management forensics investigations
LexisNexis investigates breach, notifies thousands
Senators hear call for federal cybersecurity restructuring
Former Federal Reserve Bank employee arrested
Attackers cash in on fundamental data handling mistakes, Verizon finds
Courts turn aside data breach suits

Information Security Laws, Investigations and Ethics
Cybersecurity czar candidate questions clout of new position
DHS fills National Cybersecurity Center post
FTC shutters rogue ISP for hosting malicious content, botnets
Experts optimistic of Obama cybersecurity plan
WH cybersecurity plan needs private sector guidance
Obama announces creation of cybersecurity coordinator position
Cybersecurity Act of 2009: Power grab, or necessary step?
Face-off: Who should be in charge of cybersecurity?
Feds should get private sector advice on cybersecurity
Federal efforts to secure cyberinfrastrucure

Vulnerability Risk Assessment
Are Web application penetration tests still important?
McAfee to acquire Solidcore Systems for whitelisting
The Pipe Dream of No More Free Bugs
Vulnerability test methods for application security assessments
Free HP SWFScan tool detects Adobe Flash flaws
PCI QSA assurance program penalizes assessors
Information security book excerpts and reviews
New York drafts language demanding secure code
Security experts identify 25 dangerous coding errors
Microsoft Windows XML flaw exploits test desktop antimalware
Vulnerability Risk Assessment Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bot worm  (SearchSecurity.com)
CISP-PCI  (SearchFinancialSecurity.com)
cookie poisoning  (SearchSecurity.com)
drive-by pharming  (SearchSecurity.com)
extrusion prevention  (SearchSecurity.com)
identity theft  (SearchSecurity.com)
parameter tampering  (SearchSecurity.com)
pretexting  (SearchCIO.com)
Rock Phish  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts