Showing posts with label Breach. Show all posts
Showing posts with label Breach. Show all posts

Monday, October 19, 2009

BlueCross BlueShield and Virginia DepEd Breaches

Oct. 6, 2009BlueCross BlueShield Assn.
(Chicago, IL)
A file containing identifying information for every physician in the country contracted with a Blues-affiliated insurance plan was on a laptop computer stolen from a BlueCross BlueShield Assn. employee. The file included the name, address, tax identification number and national provider identifier number for about 850,000 doctors. Some 16% to 22% of those physicians listed -- as many as 187,000 -- used their Social Security numbers as a tax ID or NPI number.187,000

Oct. 15, 2009Virginia Department of Education
(Richmond, VA)
(877) 347-5224
A flash drive containing the personal information of more than 103,000 former adult education students in Virginia was misplaced. The information included names, Social Security numbers and employment and demographic information. The flash drive contained information on all students who finished an adult education course in Virginia from April 2007 through June 2009 or who passed a high school equivalency test between January 2001 and June 2009.103,000

Monday, August 24, 2009

Radisson Hotel Data Breach

M4x: Incident happened between Nov2008 to May2009. That long ago and just reported now? What happened to Incident Monitoring, Transaction logging Audits?
Radisson Hotels Reporting Significant Data Breach
8/19/2009

The Radisson Hotel chain is the latest American retail company to announce it has suffered a significant breach of its computer systems resulting in the compromise of credit and debit card data.

In an open letter to guests on the hotel's Web site (http://www.radisson.com/openletter/openletter.html) Radisson said that the breach had occurred for a number of months, from November 2008 until May 2009, but said the investigation had not revealed how many card numbers might have been compromised. It also revealed that the data accessed may have included the name printed on a guest’s credit card or debit card, a credit or debit card number, and/or a card expiration date.

“This unauthorized access was in violation of both civil and criminal laws. Radisson has been coordinating with federal law enforcement to assist in the investigation of this incident,” wrote Fredrik Korallus, chief operating officer for the hotel and resort chain.

“While the number of potentially affected hotels involved in this incident is limited, the data accessed may have included guest information such as the name printed on a guest’s credit card or debit card, a credit or debit card number, and/or a card expiration date. We recommend that you review your account statements and credit reports closely.”

The announcement comes on the heels of news of the indictment of Albert Gonzalez, the man law enforcement alleges has been responsible for many computer security thefts and card data breaches since 2007.

http://www.cutimes.com/News/2009/8/Pages/Radisson-Hotels-Reporting-Significant-Data-Breach.aspx?PrintPreview

Thursday, August 20, 2009

Most recent breaches posted by Privacy rights Clearinghouse

This AMEX incident is troubling and the fact that this is hard to detect and control, consumers are just sittnig ducks. Well I am unaware of the complete details but many types of incidents like this go unreported. Brace yourself again, AMEX cardholders. Check you recent purchases.

Aug. 14, 2009American Express
(New York, NY)
Some American Express card members' accounts may have been compromised by an employee's recent theft of data. The former employee has been arrested and the company is investigating how the data was obtained. American Express declined to disclose any more details about the incident. The company has put additional fraud monitoring and protection controls on the accounts at issue.Unknown
Aug. 14, 2009Calhoun Area Career Center
(Battle Creek, MI)
Personal information from 455 students at Calhoun Area Career Center during the 2005-2006 school year was available online for more than three years. The information included names, Social Security numbers, 2006 addresses and telephone numbers, birth dates and school information. There were about 1,000 students at the career center during that time, but an investigation by the Calhoun County Intermediate School district found that information for 455 students was available.455
Aug. 15, 2009Northern Kentucky University
(Highland Heights, KY)
A Northern Kentucky University employee's laptop computer - which contained personal information about some current and former students -- was stolen from a restricted area. The personal information stored on the employee's computer included Social Security numbers of at least 200 current and former students.200

Thursday, August 13, 2009

Annual Cost of Breach Report from Ponemon Institute

Ponemon is Gartner to Security and Colgate to Toothpaste :) You can get a copy of the reports here:

http://securityandprivacyblog.blogspot.com/

Among the study’s key findings:

• Total costs continue to increase: The total average costs of a data breach grew to $202 per record compromised, an increase of 2.5 percent since 2007 ($197 per record) and 11 percent compared to 2006 ($182 per record). Breaches are costly events for an organization; the average total cost per reporting company was more than $6.6 million per breach (up from $6.3 million in 2007 and $4.7 million in 2006) and ranged from $613,000 to almost $32 million.

• Cost of lost business continues to carry the highest impact: The cost of lost business continued to be the most costly effect of a breach averaging $4.59 million or $139 per record compromised. Lost business now accounts for 69 percent of data breach costs, up from 65 percent in 2007, compared to 54 percent in the 2006 study.

• Third-party data breaches increase, and cost more: Breaches by third-party organizations such as outsourcers, contractors, consultants, and business partners were reported by 44 percent of respondents, up from 40 percent in 2007, up from 29 percent in 2006 and 21 percent in 2005. Per-victim cost for third-party flubs is $52 higher (e.g., $231 vs. $179) than if the breach is internally caused.

• “First timers” cost more, repeat breaches continue: Data breaches experienced by “first timers” are more expensive than those experienced by organizations that have had previous data breaches. Per-victim cost for a first time data breach is $243 vs. $192 for experienced companies. More than 84% of all cases in this year’s study involved organizations that had more than one major data breach.

• Training and awareness programs lead companies’ efforts to prevent future breaches, according to 53% of respondents. Forty-nine percent are creating additional manual procedures and controls. Of the technology options, 44% of companies have expanded their use of encryption technologies, followed by identity and access management solutions to prevent future data breaches.