<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Endpoint Security Info &#187; Data Theft &amp; Loss</title>
	<atom:link href="http://www.endpoint-security.info/category/data-theft-loss/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.endpoint-security.info</link>
	<description>Endpoint Security in the News. Learn to protect your data by controlling removable storage devices.</description>
	<lastBuildDate>Wed, 08 Feb 2012 13:33:05 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Three recently disclosed data breaches share common cause &#8211; stolen laptops</title>
		<link>http://www.endpoint-security.info/2012/02/07/three-recently-disclosed-data-breaches-share-common-cause-stolen-laptops/</link>
		<comments>http://www.endpoint-security.info/2012/02/07/three-recently-disclosed-data-breaches-share-common-cause-stolen-laptops/#comments</comments>
		<pubDate>Tue, 07 Feb 2012 12:18:05 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Encryption]]></category>
		<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[healtcare]]></category>
		<category><![CDATA[patient files]]></category>
		<category><![CDATA[stolen hardware]]></category>
		<category><![CDATA[stolen laptop]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=848</guid>
		<description><![CDATA[Stolen hardware, and particularly laptops, is still a very common cause for data breaches, especially when it comes to hospitals and other healthcare companies. Three recent incidents have all involved patient details being exposed to identity theft, fraud and other risks, after being taken together with laptops held in medical offices. While in some cases [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2012%2F02%2F07%2Fthree-recently-disclosed-data-breaches-share-common-cause-stolen-laptops%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2012%2F02%2F07%2Fthree-recently-disclosed-data-breaches-share-common-cause-stolen-laptops%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><img style="float: left; margin-right: 10px" title="stolen laptop" src="http://www.endpoint-security.info/wp-content/uploads/2012/02/stolen-laptop.jpg" alt="" width="240" height="180" />Stolen hardware, and particularly laptops, is still a very common cause for data breaches, especially when it comes to hospitals and other healthcare companies. Three recent incidents have all involved patient details being exposed to identity theft, fraud and other risks, after being taken together with laptops held in medical offices.</p>
<p>While in some cases the stolen portable computers happened to be password protected, none of them had been encrypted to better prevent access to stolen private records.<span id="more-848"></span></p>
<h3>Stolen laptop exposes medical data of over 2,000 patients</h3>
<p>A laptop computer containing medical data for 2,070 people <a href="http://www2.journalnow.com/business/2012/feb/03/1/health-provider-triumphs-laptop-stolen-in-mid-dece-ar-1888986/" target="_blank">was stolen on December 2011 from healthcare provider Triumph LLC</a> . The company which provaides psychiatric evaluations, medication monitoring, clinical assessments and outpatient therapy and is based in Raleigh, notified its clients and their families of the breach through letters mailed.</p>
<p>The laptop was stolen from the office of a Triumph manager at its operation at 725 N. Highland Ave. in Winston-Salem. The password-protected laptop, contained patient information such as names, dates of birth, medical record numbers, insurance and Medicaid numbers, billing codes and authorization status.</p>
<h3>Laptop stolen from podiatry clinic contained data on 1,500 patients</h3>
<p>A laptop, containing unencrypted personal and medical information beloging to over 1,500 people, was stolen from the <a href="http://www.bbc.co.uk/news/uk-england-hampshire-16843607" target="_blank">Walking On Air clinic in Gosport</a>. Podiatrist Natasha Townsend said the laptop did have a password. According to Ms Townsend, the laptop contains notes regarding her patients and their medical records. The laptop was most probably taken by an opportunistic thief.</p>
<h3>Laptop stolen in burglary exposes 900 Concentra patients</h3>
<p>An unencrypted laptop was stolen from the Concentra Medical Center. The computer contained names and Social Security Numbers and pre-employment work-fitness test results of <a href="http://www.concentra.com/patients/patient-security-breach.aspx" target="_blank">approximately 900 Concentra patients from the Springfield area</a>.</p>
<p>Concentra representatives believe the information has not been used inappropriately, but they have notified all the patients whose information was on the computer, and will provide them free access to a credit-monitoring service.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2010/03/08/stolen-laptop-puts-12500-patients-data-at-risk/" rel="bookmark" class="crp_title">Stolen laptop puts 12,500 patients&#8217; data at risk</a></li><li><a href="http://www.endpoint-security.info/2011/08/29/new-data-breaches-reported-by-healthcare-companies/" rel="bookmark" class="crp_title">New Data Breaches Reported by Healthcare Companies</a></li><li><a href="http://www.endpoint-security.info/2011/09/10/data-breach-roundup-missing-hardware/" rel="bookmark" class="crp_title">Data breach roundup: Missing hardware</a></li><li><a href="http://www.endpoint-security.info/2008/02/24/laptop-with-patient-data-stolen-from-nhs-hospital/" rel="bookmark" class="crp_title">Laptop with Patient Data Stolen from NHS Hospital</a></li><li><a href="http://www.endpoint-security.info/2011/05/06/plymouth-hospital-notifies-6000-patients-of-potential-security-breach/" rel="bookmark" class="crp_title">Plymouth hospital notifies 6000 patients of potential security breach</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2012/02/07/three-recently-disclosed-data-breaches-share-common-cause-stolen-laptops/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Stolen Flash Drive Exposes Data of 1,200 University of Miami Patients</title>
		<link>http://www.endpoint-security.info/2012/02/02/stolen-flash-drive-exposes-data-of-1200-university-of-miami-patients/</link>
		<comments>http://www.endpoint-security.info/2012/02/02/stolen-flash-drive-exposes-data-of-1200-university-of-miami-patients/#comments</comments>
		<pubDate>Thu, 02 Feb 2012 10:58:16 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[healthcare data breach]]></category>
		<category><![CDATA[stolen flash drive]]></category>
		<category><![CDATA[stolen hardware]]></category>
		<category><![CDATA[University of Miami]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=843</guid>
		<description><![CDATA[A security breach exposing the data of over 1,200 patients has recently been disclosed by the University of Miami. The Miller School of Medicine patient data was stolen back in November 2011, together with a flash drive, when someone broke into a pathologist’s car and took the briefcase where the portable device was stored. The [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2012%2F02%2F02%2Fstolen-flash-drive-exposes-data-of-1200-university-of-miami-patients%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2012%2F02%2F02%2Fstolen-flash-drive-exposes-data-of-1200-university-of-miami-patients%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><img style="float: left; margin-right: 10px" title="flash drive" src="http://www.endpoint-security.info/wp-content/uploads/2011/03/flash-drive.jpg" alt="" width="210" height="158" />A security breach exposing the data of over 1,200 patients <a href="http://www.miamiherald.com/2012/01/30/2615588/um-patient-data-stolen.html" target="_blank">has recently been disclosed by the University of Miami</a>. The Miller School of Medicine patient data was stolen back in November 2011, together with a flash drive, when someone broke into a pathologist’s car and took the briefcase where the portable device was stored.</p>
<p>The flash drive contained details such as age, sex, diagnosis and treatment information for patients treated from 2005 to 2011, the University of Miami disclosed in a press release. No financial information or Social Security numbers had been stored on the drive, according to the same press release.<span id="more-843"></span></p>
<blockquote><p>Following federal law, UM is informing the patients involved, according to the press release, but “there is no indication that the information was accessed or misused in any way.”</p></blockquote>
<p>The university promised to review and revise its physical and digital security policies to make sure patient data is safely stored and privacy is ensured. However, this is not the first incident they have had to deal with. Back in 2008, computer tapes with confidential information on 2.1 million patients was taken by a thief from a van transporting them. So when it comes to patient data kept in cars, the University of Miami has not changed anything in the past three years, but we can hope they will do better than empty promises next time.</p>
<p>Till the next data breach, we can surely hope so!</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/03/04/data-breaches-caused-by-storage-device-theft-hit-again/" rel="bookmark" class="crp_title">Data breaches caused by storage device theft hit again</a></li><li><a href="http://www.endpoint-security.info/2011/09/10/data-breach-roundup-missing-hardware/" rel="bookmark" class="crp_title">Data breach roundup: Missing hardware</a></li><li><a href="http://www.endpoint-security.info/2011/08/16/more-data-breaches-caused-by-improper-use-of-flash-drives-and-laptops/" rel="bookmark" class="crp_title">More data breaches caused by improper use of flash drives and laptops</a></li><li><a href="http://www.endpoint-security.info/2011/10/10/hardware-loss-in-a-hospital-endangers-data-of-1-6-million-people/" rel="bookmark" class="crp_title">Hardware loss in a hospital endangers data of 1.6 million people</a></li><li><a href="http://www.endpoint-security.info/2010/11/11/patient-records-lost-at-vincents-hospital/" rel="bookmark" class="crp_title">Patient Records Lost at Vincent’s Hospital</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2012/02/02/stolen-flash-drive-exposes-data-of-1200-university-of-miami-patients/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Stolen laptop and flash drive expose 7,000 to data theft</title>
		<link>http://www.endpoint-security.info/2012/02/01/stolen-laptop-and-flash-drive-expose-7000-to-data-theft/</link>
		<comments>http://www.endpoint-security.info/2012/02/01/stolen-laptop-and-flash-drive-expose-7000-to-data-theft/#comments</comments>
		<pubDate>Wed, 01 Feb 2012 12:59:17 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[Kansas Department of Aging]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[stolen flash drive]]></category>
		<category><![CDATA[stolen laptop]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=841</guid>
		<description><![CDATA[The Kansas Department on Aging has recently reported a hardware theft that caused a data breach affecting about 7,000 of its customers. A laptop, a flash drive and paper files were stolen out of an employee’s vehicle, putting thousands of senior customers at risk. The stolen files contained personal and protected health information belonging mainly [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2012%2F02%2F01%2Fstolen-laptop-and-flash-drive-expose-7000-to-data-theft%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2012%2F02%2F01%2Fstolen-laptop-and-flash-drive-expose-7000-to-data-theft%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>The Kansas Department on Aging has recently reported a hardware theft that caused a <a href="http://www.kwch.com/kwch-news-kah-personal-information-stolen-from-ks-department-of-aging-20120119,0,7125622.story" target="_blank">data breach affecting about 7,000 of its customers</a>. A laptop, a flash drive and paper files were stolen out of an employee’s vehicle, putting thousands of senior customers at risk.</p>
<p>The stolen files contained personal and protected health information belonging mainly to customers located in Sedgwick, Harvey, and Butler counties. The theft was immediately reported to the Wichita Police Department. The Kansas Department on Aging says it is cooperating with the police, but the stolen hardware has not yet been recovered.<span id="more-841"></span></p>
<p>Fortunately, there is no evidence to indicate that the information has been accessed and misused. The stolen data and documents may include full customer names, complete addresses, dates of birth, social security numbers, gender, in home services program participation information, Medicaid identification numbers, case management location and case manager names and telephone numbers.  No banking, credit card, or driver license information was stored on the stolen devices.</p>
<p>The Kansas Department of Aging has confirmed that at least 100 customers have had their Social Security Numbers stolen and trying to inform those affected through phone calls. They will further notify everyone affected by the breach through letters explaining the situation.</p>
<blockquote><p>&#8220;We are immediately reviewing policies and procedures relevant to information security, especially for those employees whose duties require travel off-site to prevent a similar situation from recurring,&#8221; stated Secretary Shawn Sullivan of the Department on Aging.</p></blockquote>
<p>The Department of Aging also advised their customers to contact their banks and credit card companies and let them know they are victims of a data theft, prompting them to keep an eye on any suspicious activity in the following months.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/06/20/hacks-and-stolen-hardware-top-data-breach-causes/" rel="bookmark" class="crp_title">Hacks and Stolen Hardware, Top Data Breach Causes</a></li><li><a href="http://www.endpoint-security.info/2008/04/27/credit-cart-info-of-wisebuy-customers-stolen/" rel="bookmark" class="crp_title">Credit Card Info of WiseBuy Customers Stolen</a></li><li><a href="http://www.endpoint-security.info/2008/08/12/stolen-flash-drive-with-personal-info-on-2600-delphi-workers/" rel="bookmark" class="crp_title">Stolen Flash Drive with Personal Info on 2,600 Delphi Workers</a></li><li><a href="http://www.endpoint-security.info/2011/03/16/hard-drive-with-private-information-of-nearly-90000-students-missing/" rel="bookmark" class="crp_title">Hard drive with private information of nearly 90,000 students missing</a></li><li><a href="http://www.endpoint-security.info/2011/01/03/stolen-laptop-jeopardizes-more-than-3000-patients/" rel="bookmark" class="crp_title">Stolen laptop jeopardizes more than 3000 patients</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2012/02/01/stolen-laptop-and-flash-drive-expose-7000-to-data-theft/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data breach exposes records of 1.8 million New York utilities customers</title>
		<link>http://www.endpoint-security.info/2012/01/26/data-breach-exposes-records-of-1-8-million-new-york-utilities-customers/</link>
		<comments>http://www.endpoint-security.info/2012/01/26/data-breach-exposes-records-of-1-8-million-new-york-utilities-customers/#comments</comments>
		<pubDate>Thu, 26 Jan 2012 16:40:52 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data leak]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[NY public service comission]]></category>
		<category><![CDATA[NYSEG]]></category>
		<category><![CDATA[RG&E]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=839</guid>
		<description><![CDATA[A data breach affecting 1.8 million customers of two New York utilities companies has recently been made public by the  New York State Public Service Commission. The investigation into this data breach was initiated after an employee from a third party IT company contracted by New York State Electric &#38; Gas (NYSEG) and Rochester Gas and [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2012%2F01%2F26%2Fdata-breach-exposes-records-of-1-8-million-new-york-utilities-customers%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2012%2F01%2F26%2Fdata-breach-exposes-records-of-1-8-million-new-york-utilities-customers%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>A data breach affecting 1.8 million customers of two New York utilities companies has recently been made public by the  New York State Public Service Commission. <a href="https://threatpost.com/en_us/blogs/data-breach-affects-two-million-ny-customers-state-commission-investigate-012412" target="_blank">The investigation into this data breach was initiated</a> after an employee from a third party IT company contracted by New York State Electric &amp; Gas (NYSEG) and Rochester Gas and Electric (RG&amp;E) was given unauthorized access to the company’s databases.</p>
<p>It is not clear if accessing the customer databases had any malicious intent, both affected companies claiming there was no proof of any data having been misused as a consequence of the breach. But, to stay on the safe side, they have decided to send out notifications regarding the data access, as it exposed Social Security Numbers, dates of birth and financial account information, as shown in the official <a href="http://www3.dps.ny.gov/pscweb/WebFileRoom.nsf/Web/1986D5ECA1917A8A8525798E005F81DD/$File/pr12007.pdf?OpenElement" target="_blank">press release</a> sent out by the NY Commission.<span id="more-839"></span></p>
<blockquote><p>“This investigation will seek a complete understanding of the root causes for this security breach, and the measures in place to protect against such a breach,” said the Commission&#8217;s Chairman Garry Brown.</p></blockquote>
<p>NYSEG and RG&amp;E have  also partnered with credit service group Experian to offer free credit card monitoring to the 1.8 million customers affected by the data breach. They also promised their full cooperation to forensics experts and law enforcement.</p>
<p>&nbsp;</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2012/01/24/zappos-and-amazon-face-consequences-of-data-breach/" rel="bookmark" class="crp_title">Zappos and Amazon face consequences of data breach</a></li><li><a href="http://www.endpoint-security.info/2008/09/06/real-count-ny-bank-lost-data-on-12-million-customers/" rel="bookmark" class="crp_title">Real Count: NY Bank Lost Data on 12 Million Customers</a></li><li><a href="http://www.endpoint-security.info/2010/11/01/one-million-pay-for-citibank-credit-card-account-theft/" rel="bookmark" class="crp_title">Court orders one million pay restitution for Citibank credit card accounts theft</a></li><li><a href="http://www.endpoint-security.info/2008/05/31/personal-info-on-45000-stolen-from-state-street/" rel="bookmark" class="crp_title">Personal Info on 45,000 Stolen from State Street</a></li><li><a href="http://www.endpoint-security.info/2008/05/29/breach-at-new-york-bank-exposes-millions-to-high-risks/" rel="bookmark" class="crp_title">Breach at New York Bank Exposes Millions to High Risks</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2012/01/26/data-breach-exposes-records-of-1-8-million-new-york-utilities-customers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zappos and Amazon face consequences of data breach</title>
		<link>http://www.endpoint-security.info/2012/01/24/zappos-and-amazon-face-consequences-of-data-breach/</link>
		<comments>http://www.endpoint-security.info/2012/01/24/zappos-and-amazon-face-consequences-of-data-breach/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 19:27:33 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[In the News]]></category>
		<category><![CDATA[Amazon]]></category>
		<category><![CDATA[credit card information]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[hacker attach]]></category>
		<category><![CDATA[lawsuit]]></category>
		<category><![CDATA[negligence]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[Zappos]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=834</guid>
		<description><![CDATA[When you are the lead artist of a security mishaps that ended up in a data breach affecting some 24 million people, consequences are bound to catch up with you. And they just have caught up with shoe retailer Zappos.com and the bigger online fish behind them, Amazon.com. The two companies are being sued by [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2012%2F01%2F24%2Fzappos-and-amazon-face-consequences-of-data-breach%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2012%2F01%2F24%2Fzappos-and-amazon-face-consequences-of-data-breach%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>When you are the lead artist of a security mishaps that ended up in a data breach affecting some 24 million people, consequences are bound to catch up with you. And they just have caught up with shoe retailer Zappos.com and the bigger online fish behind them, Amazon.com. <a href="http://www.darkreading.com/authentication/167901072/security/privacy/232500341/zappos-amazon-sued-over-data-breach.html" target="_blank">The two companies are being sued by the customers affected by the data breach</a>, being accused of negligence.</p>
<p>A woman from Texas seems to be the main promoter in this Kentucky lawsuit. She claims that she and millions of other customers were harmed by the exposure of their personal account information. Zappos and Amazon have not commented on the lawsuit as of earlier today. <span id="more-834"></span></p>
<p>The Zappos data breach was made public on Sunday when the company emailed employees and customers to let them know that names, phone numbers and email addresses of customers might have been accessed in a hacker attack.  The same statement reassured them that credit card and payment information had not been stolen. Zappos also advised its customers to reset account passwords on their site and any other sites where similar passwords were being used.</p>
<p>The attorneys of the Texas woman are seeking class-action status on behalf of the 24 million affected customers, claiming the security breach was actually a violation of the federal Fair Credit Reporting Act. The sum the lawsuit seeks has not been specified, but it is in the range of millions of dollars in compensatory and exemplary damages for emotional distress and loss of privacy. It also seeks to have Zappos court-ordered to pay for credit monitoring and identity theft insurance, plus periodic audits, for all those affected by the data breach.</p>
<p>&nbsp;</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2010/11/01/one-million-pay-for-citibank-credit-card-account-theft/" rel="bookmark" class="crp_title">Court orders one million pay restitution for Citibank credit card accounts theft</a></li><li><a href="http://www.endpoint-security.info/2008/06/29/montgomery-ward-kept-customers-in-the-dark-on-data-theft/" rel="bookmark" class="crp_title">Montgomery Ward Kept Customers in the Dark on Data Theft</a></li><li><a href="http://www.endpoint-security.info/2009/02/04/tjx-sale-for-data-brech/" rel="bookmark" class="crp_title">TJX finds closure for breach in big time sale</a></li><li><a href="http://www.endpoint-security.info/2012/01/26/data-breach-exposes-records-of-1-8-million-new-york-utilities-customers/" rel="bookmark" class="crp_title">Data breach exposes records of 1.8 million New York utilities customers</a></li><li><a href="http://www.endpoint-security.info/2011/07/28/hackers-will-always-have-their-stolen-data/" rel="bookmark" class="crp_title">Hackers will always have their stolen data</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2012/01/24/zappos-and-amazon-face-consequences-of-data-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ramnit worm steals 45000 Facebook users&#8217; credentials</title>
		<link>http://www.endpoint-security.info/2012/01/09/ramnit-worm-steals-45000-facebook-users-credentials/</link>
		<comments>http://www.endpoint-security.info/2012/01/09/ramnit-worm-steals-45000-facebook-users-credentials/#comments</comments>
		<pubDate>Mon, 09 Jan 2012 15:05:15 +0000</pubDate>
		<dc:creator>cristina</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[In the News]]></category>
		<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[Malware Infections]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Ramnit]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=824</guid>
		<description><![CDATA[The Ramnit worm, first discovered a year and a half ago, a malware that used to target online banking and FTP credentials, makes victims among UK and French Facebook users. A new version of the worm managed to steal more than 45000 Facebook usernames and passwords and tried to attack the e-mail accounts and virtual [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2012%2F01%2F09%2Framnit-worm-steals-45000-facebook-users-credentials%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2012%2F01%2F09%2Framnit-worm-steals-45000-facebook-users-credentials%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>The Ramnit worm, first discovered a year and a half ago, a malware that used to target online banking and FTP credentials, makes victims among UK and French Facebook users.</p>
<p>A new version of the worm managed to steal more than 45000 Facebook usernames and passwords and tried to attack the e-mail accounts and virtual private networks of affected persons. The worm has sent malicious links to victims&#8217; friends, links that downloaded malware to the person&#8217;s computer, which helped spread the worm even faster.</p>
<p>It seems like the attackers are adapting to market tendencies, targeting social networks rather than traditional communication means (such as email).</p>
<p>For more details, you can read the <a href="http://www.techweekeurope.co.uk/news/facebook-ramnit-worm-variant-stole-uk-log-in-credentials-report-claims-52733">techweekeurope.co.uk</a> report.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2010/09/20/stuxnet-worm-threatening-scada-systems-and-other-industrial-environments/" rel="bookmark" class="crp_title">Stuxnet Worm: New threat targets Scada Systems and other industrial environments</a></li><li><a href="http://www.endpoint-security.info/2011/02/04/facebook-fixes-data-theft-issue/" rel="bookmark" class="crp_title">Facebook fixes data theft issue</a></li><li><a href="http://www.endpoint-security.info/2008/12/02/us-army-bans-usb-devices-to-stop-worm-from-spreading/" rel="bookmark" class="crp_title">US Army bans USB devices to stop worm from spreading</a></li><li><a href="http://www.endpoint-security.info/2009/05/13/i-spy-with-my-little-eye/" rel="bookmark" class="crp_title">I Spy with My Little Eye&#8230;.</a></li><li><a href="http://www.endpoint-security.info/2011/01/03/new-variations-of-the-stuxnet-worm-expected-to-emerge-in-2011/" rel="bookmark" class="crp_title">New variations of the Stuxnet worm expected to emerge in 2011</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2012/01/09/ramnit-worm-steals-45000-facebook-users-credentials/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Healthcare data breaches on the rise and costing billions</title>
		<link>http://www.endpoint-security.info/2011/12/02/healthcare-data-breaches-on-the-rise-and-costing-billions/</link>
		<comments>http://www.endpoint-security.info/2011/12/02/healthcare-data-breaches-on-the-rise-and-costing-billions/#comments</comments>
		<pubDate>Fri, 02 Dec 2011 21:09:13 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[Research and Studies]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[healthcare providers]]></category>
		<category><![CDATA[hospitals]]></category>
		<category><![CDATA[Ponemon Institute]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=814</guid>
		<description><![CDATA[Based on the many stories about data breaches reported by organizations in the healthcare industry, from hospitals to insurance companies and other third-party companies that deal with healthcare data, we could have guessed this is not even close to being a top sector when it comes to data security. A new report released by the [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F12%2F02%2Fhealthcare-data-breaches-on-the-rise-and-costing-billions%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F12%2F02%2Fhealthcare-data-breaches-on-the-rise-and-costing-billions%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><img style="float: left; margin-right: 10px" title="hospital" src="http://www.endpoint-security.info/wp-content/uploads/2011/12/hospital.jpg" alt="" width="240" height="158" />Based on the many stories about data breaches reported by organizations in the healthcare industry, from hospitals to insurance companies and other third-party companies that deal with healthcare data, we could have guessed this is not even close to being a top sector when it comes to data security. <a href="http://www.darkreading.com/insider-threat/167801100/security/attacks-breaches/232200606/healthcare-data-in-critical-condition.html" target="_blank">A new report released by the Ponemon Institute</a> now brings even further insight into the state of the healthcare industry, showing a spike in data breaches of over 30% and average annual costs of 6.5 billion US dollars.</p>
<p>The &#8220;2011 Benchmark Study on Patient Privacy and Data Security,&#8221; commissioned by IDExperts, idendified employee error to be one of the main cause for data breaches in hospitals and healthcare providers. These types of organizations in the healthcare industry suffered an average of four data breaches in the past year. Nearly 30 percent of healthcare companies said the breaches they suffered resulted in medical identity theft – an over 25 percent increase over 2010.<span id="more-814"></span></p>
<p>The jump is not entirely determined by a larger number of breaches happening in the past year compared to the previous one. It&#8217;s actually the effect of better detection capabilities by healthcare organizations, <a href="http://www.darkreading.com/insider-threat/167801100/security/attacks-breaches/232200606/healthcare-data-in-critical-condition.html" target="_blank">according to Larry Ponemon, chairman and founder of the Ponemon Institute. </a></p>
<blockquote><p>&#8220;It was not too surprising that the rate of data loss increased … [But] we think that finding may not be as negative as it appears, and could be a discovery-rate increase with more control and governance practices and use of enabling technologies.&#8221;</p></blockquote>
<p>The strong increase of mobile device usage in the healthcare segment is also a high-impact factor. About 80% use such devices to gather, transmit and store patient data, and a troubling 50% don&#8217;t secure their mobile devices. The help they provide in patient care is overshadowed by the major risks to data security the patients are exposed to.</p>
<p>Nearly half of the healthcare industry breached were caused by stolen or lost computing or data devices and another 46% were caused by errors by third-party providers. Moreover, the healthcare organizations are just unaware of where patient data is stored &#8211; 61% don&#8217;t really know where all their patient data is kept. If that&#8217;s not enough, over half of them aren&#8217;t sure they actually can detect incidents where patient data is exposed.</p>
<p>Hospitals don&#8217;t lack written policies when it comes to data breach reporting &#8211; about 80% have them. Too bad about 60% consider them ineffective.</p>
<p>A full copy of the report <a href="http://www2.idexpertscorp.com/ponemon-study-2011" target="_blank">is available here for download</a>.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/08/29/new-data-breaches-reported-by-healthcare-companies/" rel="bookmark" class="crp_title">New Data Breaches Reported by Healthcare Companies</a></li><li><a href="http://www.endpoint-security.info/2010/07/27/security-breach-costs/" rel="bookmark" class="crp_title">The real cost of a security breach: 1 to 53 million USD per year</a></li><li><a href="http://www.endpoint-security.info/2011/09/10/data-breach-roundup-missing-hardware/" rel="bookmark" class="crp_title">Data breach roundup: Missing hardware</a></li><li><a href="http://www.endpoint-security.info/2012/02/07/three-recently-disclosed-data-breaches-share-common-cause-stolen-laptops/" rel="bookmark" class="crp_title">Three recently disclosed data breaches share common cause &#8211; stolen laptops</a></li><li><a href="http://www.endpoint-security.info/2009/07/23/uk-data-breaches-rise/" rel="bookmark" class="crp_title">UK data breaches on the rise</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/12/02/healthcare-data-breaches-on-the-rise-and-costing-billions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>British authorities experienced 1,035 data loss incidents</title>
		<link>http://www.endpoint-security.info/2011/11/24/british-authorities-experienced-1035-data-loss-incidents/</link>
		<comments>http://www.endpoint-security.info/2011/11/24/british-authorities-experienced-1035-data-loss-incidents/#comments</comments>
		<pubDate>Thu, 24 Nov 2011 09:05:24 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[authorities]]></category>
		<category><![CDATA[BIg Brother Watch]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[Data Security]]></category>
		<category><![CDATA[local council]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[UK]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=809</guid>
		<description><![CDATA[Only 55 of the data loss breaches have actually been reported If you can&#8217;t stop data breaches, at least cover them up! This seems to be the data security code British authorities go by. Too bad for them there is something called Freedom of Information Act requests&#8230; A new report issued by privacy campaign group [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F11%2F24%2Fbritish-authorities-experienced-1035-data-loss-incidents%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F11%2F24%2Fbritish-authorities-experienced-1035-data-loss-incidents%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><em><strong>Only 55 of the data loss breaches have actually been reported</strong></em></p>
<p>If you can&#8217;t stop data breaches, at least cover them up! This seems to be the data security code British authorities go by. Too bad for them there is something called Freedom of Information Act requests&#8230; A new report issued by privacy campaign group Big Brother Watch showed that councils across the UK experienced over a thousand data loss cases over a three year period &#8211; August 2008 to August 2011.</p>
<p>To get the information, the group sent 433 FOIs to local authorities and councils across the Great Britain and showed s shocking discrepancy between the reported 50 something incidents and the harsh reality. Not only did BBW uncover the data mishandling cases, they also requested information on what happened to the employees of said councils &#8211; if they had been disciplined, fired or prosecuted over the data breaches -, and inquired about the council&#8217;s response to each incident. <span id="more-809"></span></p>
<p>According to the 395 replies received,</p>
<blockquote><p>&#8220;We have uncovered more than 1,000 incidents across 132 local authorities, including at least 35 councils who have lost information about children and those in care,&#8221; said BBW in a <a href="http://www.bigbrotherwatch.org.uk/home/2011/11/local-authority-data-loss-exposed.html#.Tsy-109jUjw" target="_blank">statement</a> accompanying its <a href="http://bigbrotherwatch.org.uk/la-data-loss.pdf" target="_blank">report (PDF)</a>. &#8221;Highly confidential information has been treated without the proper care and respect it deserves. At least 244 laptops and portable computers were lost, while a minimum of 98 memory sticks and more than 93 mobile devices went missing.&#8221;</p></blockquote>
<p>Only 55 of the incidents were subsequently reported to the Information Commissioner&#8217;s Office, which handles data loss complaints. In only 9 cases, those involved in the data breach were fired.</p>
<blockquote><p>“I welcome this research by Big Brother Watch,&#8221; <a href="http://www.theregister.co.uk/2011/11/23/big_brother_watch_report/" target="_blank">local government minister Grant Shapps told the data protection advocates</a>. &#8221;This reinforces the need for steps to protect the privacy of law-abiding local residents. Civil liberties are under threat from the abuse of town hall surveillance powers, municipal nosy parkers rummaging through household bins and town hall officials losing sensitive personal data on children in care.”</p></blockquote>
<p>For a list of some of the most important data incidents included in the report, read the <a href="http://www.theregister.co.uk/2011/11/23/big_brother_watch_report/" target="_blank">story published by the Register</a>.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/02/25/british-local-council-gets-fine-for-mishandling-of-data/" rel="bookmark" class="crp_title">British local council gets fine for mishandling of data</a></li><li><a href="http://www.endpoint-security.info/2011/08/16/more-data-breaches-caused-by-improper-use-of-flash-drives-and-laptops/" rel="bookmark" class="crp_title">More data breaches caused by improper use of flash drives and laptops</a></li><li><a href="http://www.endpoint-security.info/2009/01/19/us-2008-data-breach-growth-blamed-on-insiders/" rel="bookmark" class="crp_title">US 2008 data breach growth blamed on insiders</a></li><li><a href="http://www.endpoint-security.info/2011/08/16/june-the-month-with-the-most-data-breaches-of-2011-so-far/" rel="bookmark" class="crp_title">June, the month with the most data breaches of 2011 so far</a></li><li><a href="http://www.endpoint-security.info/2010/05/29/uk-information-commissioners-office-reports-that-the-nhs-has-disclosed-305-security-losses-as-the-amount-of-breaches-tops-1000/" rel="bookmark" class="crp_title">UK: Information Commissioner&#8217;s Office reports that the NHS has disclosed 305 security losses, as the amount of breaches tops 1,000</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/11/24/british-authorities-experienced-1035-data-loss-incidents/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Steam hit by hackers. Are all their 35 million user accounts breached?</title>
		<link>http://www.endpoint-security.info/2011/11/14/steam-hit-by-hackers-are-all-their-35-million-user-accounts-breached/</link>
		<comments>http://www.endpoint-security.info/2011/11/14/steam-hit-by-hackers-are-all-their-35-million-user-accounts-breached/#comments</comments>
		<pubDate>Mon, 14 Nov 2011 10:29:23 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[credit cards]]></category>
		<category><![CDATA[customer database]]></category>
		<category><![CDATA[exposed user accounts]]></category>
		<category><![CDATA[gaming]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[private records]]></category>
		<category><![CDATA[Steam]]></category>
		<category><![CDATA[Valve]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=806</guid>
		<description><![CDATA[Almost two weeks ago, we revealed the major changes that had happened this year in the major data breaches top of all times. 2011 was leading in what the number of high profile of breaches is concerned. The top might change once more, ensuring an even stronger position for the current year as hackers hit [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F11%2F14%2Fsteam-hit-by-hackers-are-all-their-35-million-user-accounts-breached%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F11%2F14%2Fsteam-hit-by-hackers-are-all-their-35-million-user-accounts-breached%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Almost two weeks ago, we revealed the <a href="http://www.endpoint-security.info/2011/11/01/2011-brings-major-changes-in-the-biggest-data-breaches-of-all-times-top/" target="_blank">major changes that had happened this year in the major data breaches top of all times</a>. 2011 was leading in what the number of high profile of breaches is concerned. The top might change once more, ensuring an even stronger position for the current year as <a href="http://www.darkreading.com/database-security/167901020/security/attacks-breaches/231902879/hackers-crack-steam-database.html" target="_blank">hackers hit Steam</a>, a gaming giant that is home to 35 million user accounts.</p>
<p>What we know so far is that the Steam customer data base has been indeed accessed by hackers.</p>
<blockquote><p>&#8220;We learned that intruders obtained access to a Steam database in addition to the forums,&#8221;  said Gabe Newell, co-founder and managing director of Steam parent company Valve. &#8220;This database contained information including user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information.&#8221;</p></blockquote>
<p><span id="more-806"></span></p>
<p>While the most sensitive account information was encrypted and there is no evidence that the hackers stole any of the details in the database or that they attempted to misuse any credit cards, Valve advises users to keep a close eye on credit card activity for the time being.</p>
<blockquote><p>&#8220;We do not know of any compromised Steam accounts, so we are not planning to force a change of Steam account passwords, which are separate from forum passwords,&#8221; Newell&#8217;s statement explains. &#8220;However, it wouldn’t be a bad idea to change that as well.&#8221;</p></blockquote>
<p>Let&#8217;s all keep our fingers crossed and hope only a few forum accounts have been compromised and the 35 million records are safe.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/07/28/hackers-will-always-have-their-stolen-data/" rel="bookmark" class="crp_title">Hackers will always have their stolen data</a></li><li><a href="http://www.endpoint-security.info/2011/04/28/sony-playstation-hack/" rel="bookmark" class="crp_title">Sony’s PlayStation Network Hack Created 70 Million Potential Fraud Victims</a></li><li><a href="http://www.endpoint-security.info/2011/09/05/are-hackers-going-to-be-this-year%e2%80%99s-top-news-item/" rel="bookmark" class="crp_title">Are Hackers Going to Be This Year’s Top News Item?</a></li><li><a href="http://www.endpoint-security.info/2011/06/03/hackers-target-sony-once-more-thousands-of-customer-records-exposed/" rel="bookmark" class="crp_title">Hackers Target Sony Once More, Thousands of Customer Records Exposed</a></li><li><a href="http://www.endpoint-security.info/2011/06/22/whos-the-next-big-gaming-company-to-be-hacked/" rel="bookmark" class="crp_title">Who&#8217;s the Next Big Gaming Company to Be Hacked?</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/11/14/steam-hit-by-hackers-are-all-their-35-million-user-accounts-breached/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UK&#8217;s ICO takes serious measures to enforce data protection</title>
		<link>http://www.endpoint-security.info/2011/11/08/the-ico-takes-serious-measures-to-enforce-data-protection/</link>
		<comments>http://www.endpoint-security.info/2011/11/08/the-ico-takes-serious-measures-to-enforce-data-protection/#comments</comments>
		<pubDate>Tue, 08 Nov 2011 13:03:00 +0000</pubDate>
		<dc:creator>cristina</dc:creator>
				<category><![CDATA[Data Encryption]]></category>
		<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[In the News]]></category>
		<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[Laws & Standards]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[memory stick encryption]]></category>
		<category><![CDATA[portable device encryption]]></category>
		<category><![CDATA[Rochdale Metropolitan Borough Council]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=799</guid>
		<description><![CDATA[The ICO conducted an investigation on a case of hardware loss in May at the Rochdale Metropolitan Borough Council. The incident consisted in the loss of an unencrypted memory stick by a Council’s finance department employee, stick which contained names, addresses and payment details for 18.000 residents. The missing hardware was not found to the [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F11%2F08%2Fthe-ico-takes-serious-measures-to-enforce-data-protection%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F11%2F08%2Fthe-ico-takes-serious-measures-to-enforce-data-protection%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>The ICO conducted an investigation on a case of hardware loss in May at the Rochdale Metropolitan Borough Council. The incident consisted in the loss of an unencrypted memory stick by a Council’s finance department employee, stick which contained names, addresses and payment details for 18.000 residents. The missing hardware was not found to the date.</p>
<p>The investigation concluded that the Rochdale Council has breached the Data Protection Act by not providing employees with encrypted memory sticks (although it was a known fact that these devices would be used to transfer private information) and by not training their employees to properly use portable devices for work purposes.</p>
<p>Sally Anne Poole, ICO’s head of enforcement qualifies this mishap as ‘unacceptable’ and says ‘This incident could have been easily avoided if adequate security measures had been in place.’ in a quote by <a href="http://www.eweekeurope.co.uk/news/ico-slams-rochdale-for-data-loss-44870">eWeek</a>.</p>
<p><a href="http://www.endpointprotector.com/"><img style="border: 0pt none;" title="en-leaderboard.png" src="/wp-content/uploads/banners_2011/en-leaderboard.png" alt="en-leaderboard.png" width="472" height="59" align="middle" border="0" /></a></p>
<p>The measures taken by the ICO in this case consist of signing an undertaking of actions to take to implement data protection policies by 31<sup>st</sup> March 2012.</p>
<p>Let’s hope that more than one private data handling organization learns from this incident and encrypts their portable devices using proper <a href="http://www.endpointprotector.com/en/index.php/products/easylock">solutions</a>.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/02/25/british-local-council-gets-fine-for-mishandling-of-data/" rel="bookmark" class="crp_title">British local council gets fine for mishandling of data</a></li><li><a href="http://www.endpoint-security.info/2011/11/03/the-theft-of-laptops-doesnt-stop-organizations-dont-learn-their-lesson/" rel="bookmark" class="crp_title">The theft of laptops doesn&#8217;t stop, organizations don&#8217;t learn their lesson</a></li><li><a href="http://www.endpoint-security.info/2011/07/01/security-study-most-government-employees-fall-for-planted-usb-sticks/" rel="bookmark" class="crp_title">Security study &#8211; Most government employees fall for planted USB sticks</a></li><li><a href="http://www.endpoint-security.info/2011/04/19/edmonton-school-board-data-breach-affected-7000-people/" rel="bookmark" class="crp_title">Edmonton School Board data breach affected 7,000 people</a></li><li><a href="http://www.endpoint-security.info/2012/01/26/easylock-2-cross-platform-portable-data-encryption-solution-from-cososys/" rel="bookmark" class="crp_title">EasyLock 2 &#8211; Cross-platform portable data encryption solution from CoSoSys</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/11/08/the-ico-takes-serious-measures-to-enforce-data-protection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

