baltimoresun.com

« Businesses sexing up teens a la Miley Cyrus | Main | Spring cleaning --- and free shredding »

April 30, 2008

Who's careless with your information?

Data breaches are increasingly making headlines these days, thanks to "breach notification" laws that many states now have on the books.

Here in Maryland, the law requires businesses alert consumers when their personal information --- names, dates of birth, Social Security numbers, credit card numbers or other identifiers --- has been compromised by a lost backup tape, theft of a laptop or hard drive or the inadvertent posting of a file on a Web site.

Sometimes the breaches arise due to human error or deliberate action, such as the hacking of an online store or the incident at LendingTree.com I wrote about in today's paper. More than 56,000 Maryland consumers got letters from the company stating that former employees shared passwords for LendingTree's consumer database --- loaded with their names, social security  with three mortgage brokerages.

Consumer advocates such as Jeannine Kenney of the Consumers Union have said that such laws even the playing field for businesses because everyone has to 'fess up when there's been a problem. And because the incidents generate negative publicity, it creates incentive for companies to do a better job safeguarding your info.

"The reputational black eye could cost some future business, as well as the financial burden of notification,” she said. 

The identity theft program of the Maryland Attorney General's office now lists on its Web site the businesses that have reported security breaches. Take a look at the 67 incidents since the law took effect in January and click the link above to read copies of the letters the companies sent about the incidents:  

Case NumberDate ReceivedBusiness Name
(click to see notice)
No. of MD residentsTotal breach sizeInformation breachedHow breach occurred
15096304/23/08Verizon Wireless450 name, SSN, address, verizon wireless acct #info stolen by former employee
15096004/21/08SwimwearBoutique.com186 name, address, credit card #hacking of e-commerce website
15084304/21/08LendingTree.com568735600name, address, e-mail address, phone #, SSN, incomformer employees allowed access to unauthorized mo
15084104/21/08Sterling Commerce13 name, address, date of birth, SSN, premiums and counencrypted laptop stolen from 3rd party venndor e
15083904/21/08Columbia Capital, LLC13 name, address, SSN, banking information, Columbia password protected laptop stolen from office
       
15095604/21/08Central Collection Bureau96700000name, address, SSN, date of birth, dates of servicserver stolen from locked office
15071204/17/08SPX Corporation1329name, SSN, bank account #, routing #, account typelaptop computer stolen from subcontractor's home
15062304/14/08Gerdau Ameristeel13 name, SSN, addresshacking, unauthorized access to electronic files b
15051304/14/08Stryker Corporation23 SSNHacked internal virtual private network
15045104/10/08Interbank FX, LLC177 SSN, Driver's License #, Passport info, name, InteFile accidentally uploaded to unprotected server
15033304/09/08Agilent Technologies, Inc.26127000name, address, SSN, equity compensation infolaptop stolen from employee's car
15051204/08/08Walnut Street Securities, Inc.17 Name, address, SSN, phone #subcontractor accidentally sent client account rep
15025304/04/08Unicare17 member ID numbers (included SSN), pharmacy/medicalaccidental exposure to internet by 3rd party contr
15011404/04/08Siemens Healthcare Diagnostics Inc.1993542name, date of birth, SSNlaptop stolen from employee's home
15011104/01/08GMAC Insurance62802Name, SSN< employee ID numberstolen laptop from contactor's home, files not enc
15011004/01/08Synovus Financial Corp.3 Name, SSN, account infoloss of backup tape
14999003/31/08Okemo LLC 18401name, credit card # and expiration datehacking: intrusion into computer network
15010903/31/08Marriott International, Inc.20 Name, SSNLost data tapes
14998603/31/08Antioch University596 Name, SSN, academic records, payroll recordshacking: inauthorized access to computer between 6
14998903/28/08Museum of Science1 Name, address, credit card #'s, expiration datesOpen File inadverantly accessible through the Inte
14998803/27/08THQ, Inc.72 Name, SSN, address, employee stock purchase prograstrolen laptop, password protected, not encrypted
14986103/26/08IInfinity Pharmaceuticals, Inc.2725name, address, SSN, equity compensation infolaptop computer stolen from employee's car
14963003/25/08Genica Corporation  name, address, phone #, e-mail address, credit carhacked e-commerce site
14985903/24/08BNY Mellon Shareowner Services4690 name, address, SSN, account information, transactilost box of backup data tapes
14985803/24/08Genworth Life and Annuity Insurance Company15 name, address, date of birth, SSNcomputers stolen from office
14984803/21/08Pfizer Inc13800name, credit card #, expiration date, address, pholaptop computer stolen from home of contractor
14957303/13/08Education Management, LLC7764name, SSN, Address, date of birthlaptop stolen from office, recovered
14985403/13/08Genworth Financial Trust Company, Inc.69 name, address, SSN, account #accidentally visible through window in envelope
14918003/13/08Central Licensing Bureau2 name, SSN, address, Nebraska insurance license #report accidentally sent to wrong clients
14959003/13/08Lasell College26720000name, SSNunauthorized employee accessed database
14958703/13/08Education Management, LLC312name, address, SSNaccidentally sent spreadsheet to list of 12 stuede
14985103/12/08        
14985303/12/08MTV Networks25000name date of birth, SSN, compensation datahacking of employee's computer
14897603/11/083M131500name, SSNlaptop computer stolen from employee's car
15012903/10/08The Dental Network6997674000Name, SSN, DOB, addressPosted on company website in error
14885103/07/08Wolters Kluwer72 name, address, phone #, e-mail address, credit carHacking: unauthorized intrusion into e-commerce we
14884903/06/08Starling Insurance and Associates  name, address, SSN, DL#server stolen from office
14884803/05/08Bob Davidson Ford Lincoln Mercury, Inc.  name, address, SSN, wagesstorage tape lost enroute to payroll company
148986 03/04/08 DaVita Inc.        
14897902/28/08Nestle Waters North America1978245name,. date of birth, SSN, computer stolen from office
14898802/26/08Kraft Foods, Inc.39 name, SSNstolen laptop
14899402/15/08Syda Foundation19 Name, credit card number, expiration date, securithacking
14802502/15/08J. Lohr Vineyards & Wines1 name, SSNcomputers stolen from office
14770402/12/08Cross Country Staffing76 name, SSNlaptop computer stolen from employee's car
14754502/12/08Drexel University College of Medicine1 name, SSNlaptop computer stolen
14764202/08/08Salesforce.com9 name, SSN, date of birththeft of unencrypted external storage device
14716302/06/08NSK Americas, Inc. 2000name, SSN, salariesemployee database accidentally left unsecured on i
14754402/05/08Administrative Systems, Inc.14126 name, date of birth, SSN, bank account info for 34desktop computer stolen from office
14710002/05/08DCI Donor Services18 name, SSNlaptop stolen from Intern's home
14763902/05/08Davidson Companies 230000 hacking: gained access to a company database by sp
14738702/04/08MLSGear.com1613 name, address, credit and/or debit card # and expiHacking: used an SQL injection program to gain acc
14713202/01/08Kiwanis International257 name, credit card # and expiration date, billing/shacking: used an SQL injection virus to gain acces
14659801/28/08Invitrogen Corporation1004 name, address, SSNlaptop stolen from employee's home
14657301/28/08GE Aviation Systems5 name, SSNstolen laptop from employee's car
14657101/28/08Philips Lighting Company2 name, address, SSN, date of birthmalware virus, unauthorized access to files on lap
14656601/28/08Target Financial Services19 name, address, credit card #, SSN, phone #unauthorized access by employees of Target Nationa
14639401/24/08Mariner Healthcare2199 name, address, SSN, date of birth, salary info, 40laptop computers stolen from office
14639101/24/08Sava Senior Care2199 name, address, SSN, date of birth, salary, 401(k) password protected but unencrypted laptops stolen
14617701/22/08American Academy of Pediatrics4 name, SSN, addresslaptop computer lost during office move
14615601/22/08Science Applications International Corporation (SAIC)3 credit card # and security code, name, billing andmalicious software, hacking
14597601/16/08BJ's Wholesale Club, Inc.13 name, SSNunencrypted flash drive lost
14597401/15/08T. Rowe Price Retirement Plan Services, Inc.1470 name, SSNunencrypted computers stolen from office
14616201/10/08Johns Hopkins Health System Corporation190 name, address, date of birth, telephone #, SSN, gefile stolen from employee's car

 

Posted by Liz Kay at 12:35 PM | | Comments (0)
Categories: Consumer protection, Naughty businesses/NBotW, Technology
        

Post a comment

All comments must be approved by the blog author. Please do not resubmit comments if they do not immediately appear. You are not required to use your full name when posting, but you should use a real e-mail address. Comments may be republished in print, but we will not publish your e-mail address. Our full Terms of Service are available here.

Please enter the letter "w" in the field below:
-- ADVERTISEMENT --

Follow us on Twitter
Most Recent Comments
Baltimore Sun coverage
Personal Finance
Stay connected