A history of holes

There is no shortage of firms that have slipped up on data security

Written by IT Week staff

There have been a number of cases of firms exposing customer data in the US, only brought to light by new regulations obliging companies to disclose such problems. These included Bank of America losing an unknown number of backup tapes (February 2005), a software glitch forcing HSBC North America to tell customers of its General Motors MasterCard that their details may have been stolen (April the same year) and Ameritrade losing four backup tapes and only getting three back (also in April 2005).

One of the worst cases was in May 2005, however, when Retail Ventures reported that customer information from 108 stores in its DSW Shoe Warehouse subsidiary had been stolen. The information, involving 1.4 million credit cards used to make purchases, mostly between November and February, included account numbers, names and transaction amounts.

The issue of data and whose responsibility it is to guarantee its integrity came into focus recently when the personal searches of some 685,000 subscribers to AOL were exposed on the Web. AOL researchers had collated data – amounting to around 20 million enquiries – on an internal web site in July, but the document was soon spotted by bloggers.

Bad publicity followed, as it was proved possible to identify personal information such as the addresses and interests of individuals. In August AOL accepted the resignation of its chief technology officer Maureen Govern and also fired two other employees it held responsible for the error.

AOL’s chief executive, Jonathan Miller, attributed the breach of security to “poor judgement” by some staff, adding: “We are taking a number of additional steps, on top of our existing security systems, to help ensure this type of incident never happens again.” And a management task force was set up to decide how long AOL should retain search data, with much tighter restrictions on employee access to customer information.

Around the same time there were red faces at HSBC, when researchers at Cardiff University uncovered a vulnerability in the bank’s online system that could allow an attacker to gather all the necessary information required to enter a targetted customer account.

The New York Times revealed in June that the US National Security Agency (NSA) has been covertly monitoring millions of international bank transfers made over the Society for Worldwide Interbank Financial Telecommunication (Swift) banking network since 2001 – without court approval. According to reports, the NSA has access to confidential details including names and account numbers connected with all international money transfers which it monitors for evidence of terrorist activity. The New York Times has been heavily criticised by the White House for leaking details of the programme, while civil libertarians have criticised what they see as excessive government snooping.

Last year, research by the US consumer organisation Privacy Rights Clearinghouse indicated that over 50 million Americans may have had their personal information compromised each year due to various problems, including hacking, dishonest employees, and computers falling into the wrong hands.

Another aspect of complying with data laws was highlighted in September 2004, when the Internet Watch Foundation questioned some 1,000 senior IT managers and found 87 percent were not aware of all the legal issues concerning data and offences under the Sexual Offences Act (2003). Few, for instance, fully understood how to deal with such material as evidence, which could present particular difficulties for those working at ISPs or in systems management roles.

Another concern for firms is the need to protect staff and customers from scams spread through web sites and emails. In February the Office of Fair Trading warned that nearly half of the UK population – some 20 million consumers over the age of 15 – had been targeted by such scams, including pyramid schemes, lotteries, phishing or 419 scams. Nearly one in 10 of those targeted had actually fallen victim to the ploy and parted with money.

Tags:

reader comments

related articles

 

Eleven charged with huge identity theft

Suspects allegedly hacked unprotected wireless connections to obtain card numbers 06 Aug 2008

Dutch police nab ABN Amro hackers

14 suspects arrested on money laundering charges 21 Dec 2007

Phishers launch Monster attack on job seekers

Scam targets users of recruitment site 15 Jul 2008

related whitepapers

today's top stories

CIOs must embrace collaboration tools

Author Don Tapscott gives Angelica Mari his reasons for promoting social networking tools and says transparency is the key to security 04 Dec 2008

On a quest to build a connected society

BT Design’s JP Rangaswami talks to Gareth Morgan about his pivotal role in the telecoms giant’s efforts to deliver universal broadband and his plans to tap into the creativity of the open source community 04 Dec 2008

IT leaders must stand by India

A sense of perspective is the most important response from IT leaders to the attacks in Mumbai 04 Dec 2008

Case study: Clifford Chance

Law firm implements Sun platform and reduces datacentres to gain efficiency and cost synergies 03 Dec 2008

Should CRM be more sociable?

As vendors rush to add more social networking bells and whistles to their CRM products, some experts warn that users must tread carefully when venturing into online communities 03 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Doctors looking at a computerAnalysis

Watchdog wants IT to cure privacy woes

Information Commissioner Richard Thomas is urging organisations to put privacy protection at the top of their procurement and development criteria 04 Dec 2008

Colin McDonaldComment

Web 2.0 has potential to transform staff training

Employees can sharpen their IT skills through using the latest interactive training tools, writes Colin McDonald 04 Dec 2008

Advertisement

Primary Navigation