<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Endpoint Security Info &#187; endpoint security</title>
	<atom:link href="http://www.endpoint-security.info/category/endpoint-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.endpoint-security.info</link>
	<description>Endpoint Security in the News. Learn to protect your data by controlling removable storage devices.</description>
	<lastBuildDate>Thu, 02 Feb 2012 10:58:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Data breach exposes records of 1.8 million New York utilities customers</title>
		<link>http://www.endpoint-security.info/2012/01/26/data-breach-exposes-records-of-1-8-million-new-york-utilities-customers/</link>
		<comments>http://www.endpoint-security.info/2012/01/26/data-breach-exposes-records-of-1-8-million-new-york-utilities-customers/#comments</comments>
		<pubDate>Thu, 26 Jan 2012 16:40:52 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data leak]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[NY public service comission]]></category>
		<category><![CDATA[NYSEG]]></category>
		<category><![CDATA[RG&E]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=839</guid>
		<description><![CDATA[A data breach affecting 1.8 million customers of two New York utilities companies has recently been made public by the  New York State Public Service Commission. The investigation into this data breach was initiated after an employee from a third party IT company contracted by New York State Electric &#38; Gas (NYSEG) and Rochester Gas and [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2012%2F01%2F26%2Fdata-breach-exposes-records-of-1-8-million-new-york-utilities-customers%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2012%2F01%2F26%2Fdata-breach-exposes-records-of-1-8-million-new-york-utilities-customers%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>A data breach affecting 1.8 million customers of two New York utilities companies has recently been made public by the  New York State Public Service Commission. <a href="https://threatpost.com/en_us/blogs/data-breach-affects-two-million-ny-customers-state-commission-investigate-012412" target="_blank">The investigation into this data breach was initiated</a> after an employee from a third party IT company contracted by New York State Electric &amp; Gas (NYSEG) and Rochester Gas and Electric (RG&amp;E) was given unauthorized access to the company’s databases.</p>
<p>It is not clear if accessing the customer databases had any malicious intent, both affected companies claiming there was no proof of any data having been misused as a consequence of the breach. But, to stay on the safe side, they have decided to send out notifications regarding the data access, as it exposed Social Security Numbers, dates of birth and financial account information, as shown in the official <a href="http://www3.dps.ny.gov/pscweb/WebFileRoom.nsf/Web/1986D5ECA1917A8A8525798E005F81DD/$File/pr12007.pdf?OpenElement" target="_blank">press release</a> sent out by the NY Commission.<span id="more-839"></span></p>
<blockquote><p>“This investigation will seek a complete understanding of the root causes for this security breach, and the measures in place to protect against such a breach,” said the Commission&#8217;s Chairman Garry Brown.</p></blockquote>
<p>NYSEG and RG&amp;E have  also partnered with credit service group Experian to offer free credit card monitoring to the 1.8 million customers affected by the data breach. They also promised their full cooperation to forensics experts and law enforcement.</p>
<p>&nbsp;</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2012/01/24/zappos-and-amazon-face-consequences-of-data-breach/" rel="bookmark" class="crp_title">Zappos and Amazon face consequences of data breach</a></li><li><a href="http://www.endpoint-security.info/2010/11/01/one-million-pay-for-citibank-credit-card-account-theft/" rel="bookmark" class="crp_title">Court orders one million pay restitution for Citibank credit card accounts theft</a></li><li><a href="http://www.endpoint-security.info/2008/09/06/real-count-ny-bank-lost-data-on-12-million-customers/" rel="bookmark" class="crp_title">Real Count: NY Bank Lost Data on 12 Million Customers</a></li><li><a href="http://www.endpoint-security.info/2008/05/31/personal-info-on-45000-stolen-from-state-street/" rel="bookmark" class="crp_title">Personal Info on 45,000 Stolen from State Street</a></li><li><a href="http://www.endpoint-security.info/2008/05/29/breach-at-new-york-bank-exposes-millions-to-high-risks/" rel="bookmark" class="crp_title">Breach at New York Bank Exposes Millions to High Risks</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2012/01/26/data-breach-exposes-records-of-1-8-million-new-york-utilities-customers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security audit reveals Department of Taxation internal breaches</title>
		<link>http://www.endpoint-security.info/2011/12/18/security-audit-reveals-department-of-taxation-internal-breaches/</link>
		<comments>http://www.endpoint-security.info/2011/12/18/security-audit-reveals-department-of-taxation-internal-breaches/#comments</comments>
		<pubDate>Sun, 18 Dec 2011 08:00:34 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[DLP]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[compromised database]]></category>
		<category><![CDATA[DOTAX]]></category>
		<category><![CDATA[Hawaii DOTAX]]></category>
		<category><![CDATA[internal breach]]></category>
		<category><![CDATA[security audit]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[state department]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=819</guid>
		<description><![CDATA[The US Department of Taxation (DOTAX) decided to take a closer look at how their systems work this year. The process of evaluation included a security audit which lead to discovering internal security breaches dating back to 2008. DOTAX celebrated the three years of undiscovered breaches by putting employees of the Hawaii DOTAX on administrative [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F12%2F18%2Fsecurity-audit-reveals-department-of-taxation-internal-breaches%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F12%2F18%2Fsecurity-audit-reveals-department-of-taxation-internal-breaches%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>The US Department of Taxation (DOTAX) decided to take a closer look at how their systems work this year. The process of evaluation included a security audit which lead to <a href="http://mauinow.com/2011/12/15/department-of-taxation-security-audit-leads-to-investigation/" target="_blank">discovering internal security breaches dating back to 2008</a>. DOTAX celebrated the three years of undiscovered breaches by putting employees of the Hawaii DOTAX on administrative leave without pay and starting a comprehensive investigation.</p>
<p style="text-align: center;"><a href="http://endpointprotector.com"><img class="aligncenter" style="border-style: initial; border-color: initial; border-image: initial; border-width: 0px;" title="Device Control for Windows and Mac" src="/wp-content/uploads/banners_2011/en-336x280.jpg" alt="Device Control for Windows and Mac" width="336" height="280" align="middle" border="0" /></a></p>
<p>The breaches affected the Department’s computer tax database but no one knows when they occurred, it is suspected they happened at least as far back as 2008.The discovered incidents were immediately turned over to the Department of the Attorney General for review and investigation.<span id="more-819"></span></p>
<blockquote><p>“Protecting the integrity of tax records is a serious matter,” said Fred Pablo, the state tax director, in a written statement. “The possibility of wrongful actions are extremely disturbing, which is why these matters were immediately reported to the Attorney General.”</p></blockquote>
<p>Other than announcing some of their staff were put on administrative leave, DOTAX did not release any other details on the investigation, stating they would only do so after it had been completed.  We look forward to that moment to know how many people have been affected and what kind of protection they will receive.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/10/24/spectrum-data-theft/" rel="bookmark" class="crp_title">Spectrum Health Client Data Stolen With Hard Drive</a></li><li><a href="http://www.endpoint-security.info/2011/06/29/employee-goe-home-with-9000-records-of-coworkers/" rel="bookmark" class="crp_title">Employee goes home with 9,000 records of coworkers</a></li><li><a href="http://www.endpoint-security.info/2008/09/06/2008-sky-is-the-limit-for-us-data-breaches/" rel="bookmark" class="crp_title">2008: Sky is the Limit for US Data Breaches</a></li><li><a href="http://www.endpoint-security.info/2011/04/07/93500-midstate-medical-center-patients-affected-by-data-breach/" rel="bookmark" class="crp_title">93,500 MidState Medical Center patients affected by data breach</a></li><li><a href="http://www.endpoint-security.info/2011/08/01/short-data-breach-disclosure-windows-potentially-damaging-to-consumers/" rel="bookmark" class="crp_title">Short Data Breach Disclosure Windows, Potentially Damaging to Consumers</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/12/18/security-audit-reveals-department-of-taxation-internal-breaches/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UK&#8217;s ICO takes serious measures to enforce data protection</title>
		<link>http://www.endpoint-security.info/2011/11/08/the-ico-takes-serious-measures-to-enforce-data-protection/</link>
		<comments>http://www.endpoint-security.info/2011/11/08/the-ico-takes-serious-measures-to-enforce-data-protection/#comments</comments>
		<pubDate>Tue, 08 Nov 2011 13:03:00 +0000</pubDate>
		<dc:creator>cristina</dc:creator>
				<category><![CDATA[Data Encryption]]></category>
		<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[In the News]]></category>
		<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[Laws & Standards]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[memory stick encryption]]></category>
		<category><![CDATA[portable device encryption]]></category>
		<category><![CDATA[Rochdale Metropolitan Borough Council]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=799</guid>
		<description><![CDATA[The ICO conducted an investigation on a case of hardware loss in May at the Rochdale Metropolitan Borough Council. The incident consisted in the loss of an unencrypted memory stick by a Council’s finance department employee, stick which contained names, addresses and payment details for 18.000 residents. The missing hardware was not found to the [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F11%2F08%2Fthe-ico-takes-serious-measures-to-enforce-data-protection%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F11%2F08%2Fthe-ico-takes-serious-measures-to-enforce-data-protection%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>The ICO conducted an investigation on a case of hardware loss in May at the Rochdale Metropolitan Borough Council. The incident consisted in the loss of an unencrypted memory stick by a Council’s finance department employee, stick which contained names, addresses and payment details for 18.000 residents. The missing hardware was not found to the date.</p>
<p>The investigation concluded that the Rochdale Council has breached the Data Protection Act by not providing employees with encrypted memory sticks (although it was a known fact that these devices would be used to transfer private information) and by not training their employees to properly use portable devices for work purposes.</p>
<p>Sally Anne Poole, ICO’s head of enforcement qualifies this mishap as ‘unacceptable’ and says ‘This incident could have been easily avoided if adequate security measures had been in place.’ in a quote by <a href="http://www.eweekeurope.co.uk/news/ico-slams-rochdale-for-data-loss-44870">eWeek</a>.</p>
<p><a href="http://www.endpointprotector.com/"><img style="border: 0pt none;" title="en-leaderboard.png" src="/wp-content/uploads/banners_2011/en-leaderboard.png" alt="en-leaderboard.png" width="472" height="59" align="middle" border="0" /></a></p>
<p>The measures taken by the ICO in this case consist of signing an undertaking of actions to take to implement data protection policies by 31<sup>st</sup> March 2012.</p>
<p>Let’s hope that more than one private data handling organization learns from this incident and encrypts their portable devices using proper <a href="http://www.endpointprotector.com/en/index.php/products/easylock">solutions</a>.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/02/25/british-local-council-gets-fine-for-mishandling-of-data/" rel="bookmark" class="crp_title">British local council gets fine for mishandling of data</a></li><li><a href="http://www.endpoint-security.info/2011/11/03/the-theft-of-laptops-doesnt-stop-organizations-dont-learn-their-lesson/" rel="bookmark" class="crp_title">The theft of laptops doesn&#8217;t stop, organizations don&#8217;t learn their lesson</a></li><li><a href="http://www.endpoint-security.info/2011/07/01/security-study-most-government-employees-fall-for-planted-usb-sticks/" rel="bookmark" class="crp_title">Security study &#8211; Most government employees fall for planted USB sticks</a></li><li><a href="http://www.endpoint-security.info/2011/04/19/edmonton-school-board-data-breach-affected-7000-people/" rel="bookmark" class="crp_title">Edmonton School Board data breach affected 7,000 people</a></li><li><a href="http://www.endpoint-security.info/2012/01/26/easylock-2-cross-platform-portable-data-encryption-solution-from-cososys/" rel="bookmark" class="crp_title">EasyLock 2 &#8211; Cross-platform portable data encryption solution from CoSoSys</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/11/08/the-ico-takes-serious-measures-to-enforce-data-protection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The theft of laptops doesn&#8217;t stop, organizations don&#8217;t learn their lesson</title>
		<link>http://www.endpoint-security.info/2011/11/03/the-theft-of-laptops-doesnt-stop-organizations-dont-learn-their-lesson/</link>
		<comments>http://www.endpoint-security.info/2011/11/03/the-theft-of-laptops-doesnt-stop-organizations-dont-learn-their-lesson/#comments</comments>
		<pubDate>Thu, 03 Nov 2011 15:44:38 +0000</pubDate>
		<dc:creator>cristina</dc:creator>
				<category><![CDATA[Data Encryption]]></category>
		<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[In the News]]></category>
		<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[device monitoring]]></category>
		<category><![CDATA[encrypt data]]></category>
		<category><![CDATA[encyption]]></category>
		<category><![CDATA[hardware loss]]></category>
		<category><![CDATA[ICO]]></category>
		<category><![CDATA[laptop lost]]></category>
		<category><![CDATA[portable device use]]></category>
		<category><![CDATA[track use of portable devices]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=795</guid>
		<description><![CDATA[A whole lot was written on loss/theft of hardware (laptops, USB sticks, external hard drives, etc.) and we had thought that organizations would learn their lesson and encrypt sensitive data on such supports. Apparently, things aren&#8217;t quite like that and two recent incidents come to prove it. A resident student at Vancouver Coastal Health lost [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F11%2F03%2Fthe-theft-of-laptops-doesnt-stop-organizations-dont-learn-their-lesson%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F11%2F03%2Fthe-theft-of-laptops-doesnt-stop-organizations-dont-learn-their-lesson%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>A whole lot was written on loss/theft of hardware (laptops, USB sticks, external hard drives, etc.) and we had thought that organizations would learn their lesson and encrypt sensitive data on such supports. Apparently, things aren&#8217;t quite like that and two recent incidents come to prove it.</p>
<p>A resident student at Vancouver Coastal Health lost a <a href="http://www.ctvbc.ctv.ca/servlet/an/local/CTVNews/20111027/bc_steele_privacy_breach_111027/20111027/?hub=BritishColumbiaHome">laptop and a USB stick</a> (there is a high probability that the hardware was stolen) at the Toronto Airport. The information stored on the drives was password protected but it wasn&#8217;t encrypted.</p>
<p>A Vancouver Coastal Health official calls the incident &#8216;unfortunate&#8217; and says that &#8216;This is the way physicians and other health care workers need to do their job. They need to use these devices.&#8217; He admits that many professionals use laptops and that the agency has some issues handling mobile technologies.</p>
<p>Another mishap took place in the United Kingdom and the <a href="http://www.guardian.co.uk/government-computing-network/2011/oct/28/newcastle-youth-offending-team-data-breach-ico">theft of a laptop</a> that stored personal information of 100 young people who participated in inclusion programs. This laptop was in the house of a contractor of the Newcastle Youth Offending Team organization. The ICO (Information Commissioner&#8217;s Office) has established a fine for this organization for not encrypting the data. According to Sally-Anne Poole &#8216;Encryption is a basic procedure and an inexpensive way to ensure that information is kept secure.&#8217; She underlines the fact that organizations working with contractors must make sure that the latter ones align to their security policies.</p>
<p>It&#8217;s so simple and cheap to <a href="http://www.endpointprotector.com/">track the use of portable devices</a> and <a href="http://www.endpointprotector.com/en/index.php/products/easylock">encrypt sensitive data</a> stored on them, that we really ask ourselves why don&#8217;t organizations do it?</p>
<p>Let&#8217;s hope that at least legal constraints will force private data handlers to implement solutions and politics to maintain their data safe and secure.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/11/08/the-ico-takes-serious-measures-to-enforce-data-protection/" rel="bookmark" class="crp_title">UK&#8217;s ICO takes serious measures to enforce data protection</a></li><li><a href="http://www.endpoint-security.info/2008/11/13/self-encrypting-laptop-from-dell/" rel="bookmark" class="crp_title">Self-encrypting laptop from Dell</a></li><li><a href="http://www.endpoint-security.info/2008/10/20/deloitte-lost-hundreds-of-thousands-of-pension-details/" rel="bookmark" class="crp_title">Deloitte Lost Hundreds of Thousands of Pension Details</a></li><li><a href="http://www.endpoint-security.info/2011/02/25/british-local-council-gets-fine-for-mishandling-of-data/" rel="bookmark" class="crp_title">British local council gets fine for mishandling of data</a></li><li><a href="http://www.endpoint-security.info/2011/09/10/data-breach-roundup-missing-hardware/" rel="bookmark" class="crp_title">Data breach roundup: Missing hardware</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/11/03/the-theft-of-laptops-doesnt-stop-organizations-dont-learn-their-lesson/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2011 Brings Major Changes in the Biggest Data Breaches of All Times Top</title>
		<link>http://www.endpoint-security.info/2011/11/01/2011-brings-major-changes-in-the-biggest-data-breaches-of-all-times-top/</link>
		<comments>http://www.endpoint-security.info/2011/11/01/2011-brings-major-changes-in-the-biggest-data-breaches-of-all-times-top/#comments</comments>
		<pubDate>Tue, 01 Nov 2011 08:41:51 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[exposed data]]></category>
		<category><![CDATA[largest data breaches]]></category>
		<category><![CDATA[top data breaches]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=775</guid>
		<description><![CDATA[While data breaches are as common as any other daily occurrence in the business and individual worlds, the large security incidents don&#8217;t happen as often, especially if you think that one of the breaches in the top ten all time largest data exposures dates back to 1984. 2011 is not yet over and it already is [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F11%2F01%2F2011-brings-major-changes-in-the-biggest-data-breaches-of-all-times-top%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F11%2F01%2F2011-brings-major-changes-in-the-biggest-data-breaches-of-all-times-top%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>While data breaches are as common as any other daily occurrence in the business and individual worlds, the large security incidents don&#8217;t happen as often, especially if you think that one of the breaches in the top ten all time largest data exposures dates back to 1984. 2011 is not yet over and it already is the poster child of this <a href="http://datalossdb.org/index/largest" target="_blank">top we all want to see unchanged</a>.</p>
<p>2011 is the only year with three major data loss incidents in the top ten: Sony Corporation with 77 million records exposed, SK Communications, Nate, Cyworld with 35 million and again Sony Corporation through their Sony Online Entertainment division with close to 25 million records exposed. Luckily for us, although it featured large incidents, 2011 did not create as many victims as 2009 with its two incidents, Heartland Payment Systems, Tower Federal Credit Union, Beverly National Bank which share the number one position in the infamous top with 130 million records exposed and RockYou Inc. with another 32 million. <span id="more-775"></span></p>
<p>Here&#8217;s the <a href="http://datalossdb.org/" target="_blank">ultimate data breach top</a>, the place where you never want to see your company&#8217;s name or that of any other company that has your data stored:</p>
<ol>
<li>Heartland Payment Systems, Tower Federal Credit Union, Beverly National Bank &#8211; 130 million records (2009)</li>
<li>TJX Companies Inc. &#8211; 94 million records (2007)</li>
<li>TRW, Sears Roebuck &#8211; 90 million records (1984)</li>
<li>Sony Corporation &#8211; 77 million records (2011)</li>
<li>CardSystems, Visa, MasterCard, American Express &#8211; 40 million records (2005)</li>
<li>SK Communications, Nate, Cyworld &#8211; 35 million records (2011)</li>
<li>RockYou Inc. &#8211; 32 million records (2009)</li>
<li>U.S. Department of Veterans Affairs &#8211; 26,5 million (2006)</li>
<li>HM Revenue and Customs, TNT &#8211; 25 million records (2007)</li>
<li>Sony Online Entertainment, Sony Corporation &#8211; 24,6 million (2011)</li>
</ol>
<div>For those of you who might still think hacking is fun and cool, 8 of these incidents were the result of hacking. Another two were caused by a stolen computer and a lost media storing private data. Let&#8217;s all hope nothing major happens in these last two months of 2011 and that this top remains unchanged for a long, very long time!</div>
<p>&nbsp;</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/08/16/june-the-month-with-the-most-data-breaches-of-2011-so-far/" rel="bookmark" class="crp_title">June, the month with the most data breaches of 2011 so far</a></li><li><a href="http://www.endpoint-security.info/2011/11/14/steam-hit-by-hackers-are-all-their-35-million-user-accounts-breached/" rel="bookmark" class="crp_title">Steam hit by hackers. Are all their 35 million user accounts breached?</a></li><li><a href="http://www.endpoint-security.info/2011/04/25/data-breaches-down-but-threat-still-real/" rel="bookmark" class="crp_title">Data Breaches Down, But Threat Still Real</a></li><li><a href="http://www.endpoint-security.info/2011/04/28/sony-playstation-hack/" rel="bookmark" class="crp_title">Sony’s PlayStation Network Hack Created 70 Million Potential Fraud Victims</a></li><li><a href="http://www.endpoint-security.info/2009/01/19/us-2008-data-breach-growth-blamed-on-insiders/" rel="bookmark" class="crp_title">US 2008 data breach growth blamed on insiders</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/11/01/2011-brings-major-changes-in-the-biggest-data-breaches-of-all-times-top/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>CoSoSys Releases Endpoint Protector 4 – New Device Control Hardware and Virtual Appliance</title>
		<link>http://www.endpoint-security.info/2011/10/27/cososys-releases-endpoint-protector-4-%e2%80%93-new-device-control-hardware-and-virtual-appliance/</link>
		<comments>http://www.endpoint-security.info/2011/10/27/cososys-releases-endpoint-protector-4-%e2%80%93-new-device-control-hardware-and-virtual-appliance/#comments</comments>
		<pubDate>Thu, 27 Oct 2011 11:04:33 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Encryption]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[CoSoSys]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[Device Control]]></category>
		<category><![CDATA[Endpoint Protector]]></category>
		<category><![CDATA[Endpoint Protector 4]]></category>
		<category><![CDATA[EPP 4]]></category>
		<category><![CDATA[hardware appliance]]></category>
		<category><![CDATA[product release]]></category>
		<category><![CDATA[virtual appliance]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=773</guid>
		<description><![CDATA[Endpoint security developer CoSoSys has released a new version of their data loss prevention, device control and endpoint security solution for Windows and Mac OS, Endpoint Protector. Offering enhanced protection, increased effectiveness and the fastest implementation time in its segment, the out-of-the-box Hardware and Virtual Appliance is now available for small, medium and large companies [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F10%2F27%2Fcososys-releases-endpoint-protector-4-%25e2%2580%2593-new-device-control-hardware-and-virtual-appliance%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F10%2F27%2Fcososys-releases-endpoint-protector-4-%25e2%2580%2593-new-device-control-hardware-and-virtual-appliance%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Endpoint security developer CoSoSys has released a new version of their <a href="http://endpointprotector.com" target="_blank">data loss prevention, device control and endpoint security solution</a> for Windows and Mac OS, Endpoint Protector. Offering enhanced protection, increased effectiveness and the fastest implementation time in its segment, the out-of-the-box Hardware and Virtual Appliance is now available for small, medium and large companies and organizations.</p>
<p><a href="http://endpointprotector.com" target="_blank"><img title="en-banner.png" src="/wp-content/uploads/banners_2011/en-banner.png" alt="en-banner.png" width="468" height="60" align="middle" border="0" /></a></p>
<p>Coming with a long list of new features targeting better security, reliability, ease of use and better adapting to company structures and organization charts, Endpoint Protector 4 is designed to protect networks ranging from 20 computers (endpoints) to more than 5.000 endpoints.</p>
<p>Some of the top benefits of this latest Endpoint Protector solution are:</p>
<ul>
<li>Seamless integration in business processes</li>
<li>Saving time and money when the solution is installed</li>
<li>Increased security through enhanced protection</li>
<li>Reducing allotted resources of the security staff</li>
<li>Optimum security through enhanced stability</li>
<li>Enhanced protection through complex, adaptable end efficient security</li>
<li>Reliable security through enhanced monitoring and policy control</li>
</ul>
<div>To find out more about the Endpoint Protector 4 Hardware and Virtual Appliance and see the detailed list of features, visit the <a href="http://www.endpointprotector.com/en/index.php/products/endpoint_protector_appliance" target="_blank">product page</a> and the <a href="http://www.cososys.com/press_releases/Press_Release_Endpoint_Protector_4-Device_Control_Hardware_and_Virtual_Appliance_27-Oct-2011_EN.html" target="_blank">official press release</a>.</div>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2010/05/27/my-endpoint-protector-in-japan/" rel="bookmark" class="crp_title">My Endpoint Protector makes its way into Japan</a></li><li><a href="http://www.endpoint-security.info/2012/01/26/easylock-2-cross-platform-portable-data-encryption-solution-from-cososys/" rel="bookmark" class="crp_title">EasyLock 2 &#8211; Cross-platform portable data encryption solution from CoSoSys</a></li><li><a href="http://www.endpoint-security.info/2009/10/16/new-zealands-leading-payment-provider-secures-devices-with-endpoint-protector/" rel="bookmark" class="crp_title">New Zealands leading payment provider secures devices with Endpoint Protector</a></li><li><a href="http://www.endpoint-security.info/2010/10/13/endpoint-protector-2009-for-mac-introduces-file-tracing-for-portable-devices/" rel="bookmark" class="crp_title">Endpoint Protector 2009 for Mac Introduces File Tracing for Portable Devices</a></li><li><a href="http://www.endpoint-security.info/2009/06/30/cososys-launches-worlds-first-dlp-and-endpoint-security-saas-offering/" rel="bookmark" class="crp_title">CoSoSys Launches World&#8217;s First DLP and Endpoint Security SaaS Offering</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/10/27/cososys-releases-endpoint-protector-4-%e2%80%93-new-device-control-hardware-and-virtual-appliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Access to Company Data: Why Employees Are Not All Equal</title>
		<link>http://www.endpoint-security.info/2011/08/26/access-to-company-data-why-employees-are-not-all-equal/</link>
		<comments>http://www.endpoint-security.info/2011/08/26/access-to-company-data-why-employees-are-not-all-equal/#comments</comments>
		<pubDate>Fri, 26 Aug 2011 16:34:00 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[data access]]></category>
		<category><![CDATA[data loss prevention]]></category>
		<category><![CDATA[Data Security]]></category>
		<category><![CDATA[employee privileges]]></category>
		<category><![CDATA[Endpoint Protector]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=728</guid>
		<description><![CDATA[Here&#8217;s a good piece of news for companies around the world: when it comes to access to your important and confidential data, you don’t need to treat all employees as equals. In fact, it is highly recommended to make sure not anyone can access all your files, and if they can see them, you should [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F08%2F26%2Faccess-to-company-data-why-employees-are-not-all-equal%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F08%2F26%2Faccess-to-company-data-why-employees-are-not-all-equal%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Here&#8217;s a good piece of news for companies around the world: when it comes to <strong>access to your important and confidential data, you don’t need to treat all employees as equals</strong>. In fact, it is highly recommended to make sure not anyone can access all your files, and if they can see them, you should prevent everyone from copying or transferring the information you need to keep private.</p>
<p><a href="http://endpointprotector.com"><img style="border: 0px initial initial;" title="en-banner.png" src="/wp-content/uploads/banners_2011/en-banner.png" border="0" alt="en-banner.png" width="468" height="60" align="middle" /></a></p>
<p>Ongoing projects, customer data bases, inventions, strategies, private records of employees, credit card and bank account information, all these must remain confidential. So if you store them, how can you make sure an employee that is unaware of the harm they are doing or who knowingly wants to harm you, fails at their attempt to expose the files in question?<span id="more-728"></span></p>
<p>The feature that enables you to take control of who does what with your data is called <a href="http://www.endpointprotector.com/en/index.php/products/endpoint_protector" target="_blank">File Whitelisting</a>. Backed by file tracing, not only do you see who transfers what and to where, you also prevent anyone from copying or transferring documents classified as restricted to being viewed only. It keeps you safe and it also lets you know who tried to stick their nose where they were not supposed to. An <a href="http://www.endpointprotector.com/" target="_blank">effective endpoint security, device control and data loss prevention solution </a>will certainly offer your company these seemingly simple, but very powerful features.</p>
<p>What’s the alternative? You might end up in the same situation as <a href="http://www.cleveland.com/university-heights/index.ssf/2011/08/business_owners_report_theft_o.html" target="_blank">Chocolate Emporium who had their entire customer database being transferred by an employee via Dropbox</a>. Yes, large files no longer discourage anyone. A simple flash drive or smartphone is enough to store all the information you value the most, in a matter of minutes. In the case of Chocolate Emporium, the employee knew what he was doing and took all the information on buyers he could find. But in some cases, there is no malicious intent. An eager employee that’s not educated in the ways of security my copy a similar database on his portable hard drive to work from home, to only find himself the victim of a theft. With the hardware also goes the information, which in most cases is unencrypted.</p>
<p>So keep your company safe instead of making up for the loss. It’s easy and effective. So why not try it?</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/06/29/employee-goe-home-with-9000-records-of-coworkers/" rel="bookmark" class="crp_title">Employee goes home with 9,000 records of coworkers</a></li><li><a href="http://www.endpoint-security.info/2010/10/13/endpoint-protector-2009-for-mac-introduces-file-tracing-for-portable-devices/" rel="bookmark" class="crp_title">Endpoint Protector 2009 for Mac Introduces File Tracing for Portable Devices</a></li><li><a href="http://www.endpoint-security.info/2010/11/05/insiders-frequent-source-of-corporate-fraud-incidents/" rel="bookmark" class="crp_title">Insiders, frequent source of corporate fraud incidents</a></li><li><a href="http://www.endpoint-security.info/2010/03/05/ftc-issues-data-loss-over-p2p-warning/" rel="bookmark" class="crp_title">FTC issues warning about data loss over P2P</a></li><li><a href="http://www.endpoint-security.info/2010/01/25/usb-ports-smart-security-solution/" rel="bookmark" class="crp_title">Why cutting off USB ports is not a smart security solution</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/08/26/access-to-company-data-why-employees-are-not-all-equal/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More data breaches caused by improper use of flash drives and laptops</title>
		<link>http://www.endpoint-security.info/2011/08/16/more-data-breaches-caused-by-improper-use-of-flash-drives-and-laptops/</link>
		<comments>http://www.endpoint-security.info/2011/08/16/more-data-breaches-caused-by-improper-use-of-flash-drives-and-laptops/#comments</comments>
		<pubDate>Tue, 16 Aug 2011 09:39:54 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[flash drive]]></category>
		<category><![CDATA[laptop]]></category>
		<category><![CDATA[lost data]]></category>
		<category><![CDATA[unencrypted data]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=716</guid>
		<description><![CDATA[The beginning of August has been extremely rich in data breaches caused by stolen or misplaced flash drives, hard drives and laptops, most of them unencrypted, as it almost always happens. Some of them are quite recent, in other cases it has taken over 5 months for those in question to let the affected parties [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F08%2F16%2Fmore-data-breaches-caused-by-improper-use-of-flash-drives-and-laptops%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F08%2F16%2Fmore-data-breaches-caused-by-improper-use-of-flash-drives-and-laptops%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>The beginning of August has been extremely rich in data breaches caused by stolen or misplaced flash drives, hard drives and laptops, most of them unencrypted, as it almost always happens. Some of them are quite recent, in other cases it has taken over 5 months for those in question to let the affected parties know about the incidents.</p>
<p><a href="http://endpointprotector.com"><img style="border: 0px initial initial;" title="en-banner.png" src="/wp-content/uploads/banners_2011/en-banner.png" border="0" alt="en-banner.png" width="468" height="60" align="middle" /></a></p>
<p>The first breach in chronological order affected Lewisham Homes Limited and Wandle Housing Association Ltd and it involved a contractor’s <a href="http://www.databreaches.net/?p=20010" target="_blank">flash drive that got lost in a pub</a>. Apparently, mixing drinking and having fun with sensitive information does not lead to a tasty cocktail, it leads to details of over 26,000 tenants being lost. The silver lining of the incident is that only 800 people should worry about bank details.<span id="more-716"></span> August 5 was by far the most prolific day for security breach reports with several such incidents being reported on that very day, two of which had to do with missing drives and computers. In the first case, <a href="http://datalossdb.org/incidents/4498-two-unencrypted-laptops-with-patient-information-stolen-from-hospital" target="_blank">two unencrypted laptops</a> with patient information were stolen from the Harley Street Clinic. In the second case, a <a href="http://www.boston.com/Boston/whitecoatnotes/2011/08/data-breach-reported-brigham-and-women-faulkner/lCj8ZNSrUUb4BnNzO3NnBL/index.html" target="_blank">hard drive with medical information of over 600 patients</a> was left in a cab by a doctor in a great hurry.</p>
<p>Another laptop was stolen from the Office of the Telecommunication Authority, which contained <a href="http://rthk.hk/rthk/news/englishnews/20110812/news_20110812_56_776496.htm" target="_blank">personal data of more than 500 people</a>. It was closely followed by <a href="http://datalossdb.org/incidents/4507-doctor-lost-unencrypted-flash-drive-with-474-maternity-patients-names-and-medical-details" target="_blank">another flash drive, again unencrypted, belonging to a hospital</a> that a doctor managed to lose. It contained 474 maternity patients&#8217; names and medical details.</p>
<p>So, my advice to you: make sure everything is encrypted: your portable hard drives, your flash drives, your laptops and anything else you can think of. Better to prevent data loss than deal with it after the security breach has occurred. If you need help finding a <a href="http://endpointprotector.com" target="_blank">device control and data loss prevention solution</a>, we’re always here to help!</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/03/04/data-breaches-caused-by-storage-device-theft-hit-again/" rel="bookmark" class="crp_title">Data breaches caused by storage device theft hit again</a></li><li><a href="http://www.endpoint-security.info/2011/09/10/data-breach-roundup-missing-hardware/" rel="bookmark" class="crp_title">Data breach roundup: Missing hardware</a></li><li><a href="http://www.endpoint-security.info/2011/04/07/93500-midstate-medical-center-patients-affected-by-data-breach/" rel="bookmark" class="crp_title">93,500 MidState Medical Center patients affected by data breach</a></li><li><a href="http://www.endpoint-security.info/2011/05/23/loss-or-theft-of-hardware-still-important-cause-for-data-breaches-in-health-sector/" rel="bookmark" class="crp_title">Loss or theft of hardware, still important cause for data breaches in health sector</a></li><li><a href="http://www.endpoint-security.info/2012/02/02/stolen-flash-drive-exposes-data-of-1200-university-of-miami-patients/" rel="bookmark" class="crp_title">Stolen Flash Drive Exposes Data of 1,200 University of Miami Patients</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/08/16/more-data-breaches-caused-by-improper-use-of-flash-drives-and-laptops/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Monday Endpoint Security and DLP Roundup #1</title>
		<link>http://www.endpoint-security.info/2011/07/18/monday-endpoint-security-dlp-roundup-1/</link>
		<comments>http://www.endpoint-security.info/2011/07/18/monday-endpoint-security-dlp-roundup-1/#comments</comments>
		<pubDate>Mon, 18 Jul 2011 07:03:37 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[health care]]></category>
		<category><![CDATA[inside threats]]></category>
		<category><![CDATA[stolen data]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=685</guid>
		<description><![CDATA[The weekend brings news of several security breaches, some showing a trend, others just containing very real warnings. As the week starts, here&#8217;s what you might have missed over the weekend, to keep you alert and informed. Today&#8217;s roundup brings you a few employees gone rogue on corporate data, sensitive information posted online, again the [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F07%2F18%2Fmonday-endpoint-security-dlp-roundup-1%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F07%2F18%2Fmonday-endpoint-security-dlp-roundup-1%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><img style="border: 0px initial initial;" title="en-250x250.png" src="http://www.endpoint-security.info/wp-content/uploads/banners_2011/en-250x250.png" border="0" alt="en-250x250.png" width="225" height="225" align="left" />The weekend brings news of several security breaches, some showing a trend, others just containing very real warnings. As the week starts, here&#8217;s what you might have missed over the weekend, to keep you alert and informed. Today&#8217;s roundup brings you a few employees gone rogue on corporate data, sensitive information posted online, again the ever present stolen laptop and quite a few of these mishaps happening in institutions related to health care.</p>
<p>A security breach that happened back in April finally surfaced and it involves <a href="http://www.theregister.co.uk/2011/07/16/medvet_web_incompetence/print.html" target="_blank">South Australian DNA testing company Medvet</a>. The mishap led to customers&#8217; names, work and home addresses, and types of DNA testing kit ordered being exposed online and dutifully indexed by Google. Australia’s Privacy Commissioner Tim Pilgrim has already launched an investigation.</p>
<p><span id="more-685"></span></p>
<p>The <a href="http://www.thejournal.ie/meath-council-posted-personal-info-of-planning-applicants-online-report-178779-Jul2011/" target="_blank">Meath County Council</a> followed in the steps of the Australian security breach when planning applicants&#8217; personal information, including birth certificates, bank account details and drivers&#8217; licenses were posted online on their website. It took notifications from the general public for the information to be taken down.</p>
<p><a href="http://www.msnbc.msn.com/id/43775666/ns/local_news-indianapolis_in/t/parents-worried-about-info-breach-college-savings-program/" target="_blank">UPromise Investments</a> is one of the companies where employees thought to go against the employer in a security breach. The person in question accessed accessed 300 depositors&#8217; names, social security numbers, birthdays and other contact information. This happened over 7 months while the suspected employee was on the job. What the job was? Withdrawals and deposits of course! The other such case happened at the <a href="http://datalossdb.org/incidents/4446-employee-accessed-188-patients-records-without-authorization" target="_blank">Haartman Hospital</a>, where an employee accessed 188 patients&#8217; records without authorization.</p>
<p>The ever present stolen laptop this time belonged to the <a href="http://www.examiner.co.uk/news/local-west-yorkshire-news/2011/07/16/confidential-kirklees-council-files-on-computer-stolen-by-burglars-86081-29062633/" target="_blank">Kirklees Council</a> and contained confidential files on 25 employees. What&#8217;s even more shocking is that this is one of several incidents in which private data was lost by the authority. If you were wondering, none of the information was encrypted and no one at the Council had to explain themselves for these breaches. Classic case of never learning from past mistakes!</p>
<p>Have a safe week everyone!</p>
<p>&nbsp;</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2011/02/25/british-local-council-gets-fine-for-mishandling-of-data/" rel="bookmark" class="crp_title">British local council gets fine for mishandling of data</a></li><li><a href="http://www.endpoint-security.info/2011/09/10/data-breach-roundup-missing-hardware/" rel="bookmark" class="crp_title">Data breach roundup: Missing hardware</a></li><li><a href="http://www.endpoint-security.info/2011/06/20/hacks-and-stolen-hardware-top-data-breach-causes/" rel="bookmark" class="crp_title">Hacks and Stolen Hardware, Top Data Breach Causes</a></li><li><a href="http://www.endpoint-security.info/2011/09/29/us-postal-services-misplaced-cd-with-data-on-4000-people/" rel="bookmark" class="crp_title">US Postal Services misplaced CD with data on 4000 people</a></li><li><a href="http://www.endpoint-security.info/2011/03/04/data-breaches-caused-by-storage-device-theft-hit-again/" rel="bookmark" class="crp_title">Data breaches caused by storage device theft hit again</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/07/18/monday-endpoint-security-dlp-roundup-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Employee goes home with 9,000 records of coworkers</title>
		<link>http://www.endpoint-security.info/2011/06/29/employee-goe-home-with-9000-records-of-coworkers/</link>
		<comments>http://www.endpoint-security.info/2011/06/29/employee-goe-home-with-9000-records-of-coworkers/#comments</comments>
		<pubDate>Wed, 29 Jun 2011 05:23:21 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[endpoint security]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[healthcare]]></category>
		<category><![CDATA[healthcare breaches]]></category>
		<category><![CDATA[insider threat]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=678</guid>
		<description><![CDATA[An employee of the California Department of Health thought it would be a great idea to access and copy to a portable drive personal information belonging to 9,000 former and current state employees.  The security breach discovered within the department involved names, dates of birth, and addresses stored in compensation records of the affected parties. The [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F06%2F29%2Femployee-goe-home-with-9000-records-of-coworkers%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2011%2F06%2F29%2Femployee-goe-home-with-9000-records-of-coworkers%2F&amp;source=cososys&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>An employee of the California Department of Health thought it would be a great idea to access and copy to a portable drive personal information belonging to <a href="http://datalossdb.org/incidents/3941-personal-and-workers-compensation-information-of-approximately-9-000-current-and-former-state-employees-copied-to-a-drive-by-an-employee-and-removed-from-offices" target="_blank">9,000 former and current state employees</a>.  The security breach discovered within the department involved names, dates of birth, and addresses stored in compensation records of the affected parties.</p>
<p><a href="http://www.endpointprotector.com/lp/endpoint_protector_general_EN.php"><img title="Endpoint Security and Device Control Solutions with low TCO and great ROI." src="/wp-content/uploads/banners/banner-galactic-red-epp.jpg" border="0" alt="Endpoint Security and Device Control Solutions with low TCO and great ROI." width="500" height="100" align="middle" /></a></p>
<p>The California Department of Health is currently running an investigation on the scope and extent of the breach. In the mean time, the person responsible for the unauthorized removal of personal records from the institution is on administrative leave, answering all the questions needed to understand the incident. <span id="more-678"></span></p>
<p>The data breach was discovered due to a state security detection system, which alerted officials of potentially suspicious activity back in April. The department stated they have upgraded their security to prevent future such security incidents.</p>
<p>Is there an easy way to prevent such breaches? An <a href="http://endpointprotector.com/" target="_blank">endpoint security and data loss prevention solution</a>, if it&#8217;s a top line one, involves file tracing, telling IT departments who copied what and to which device. It also prevents the use of unauthorized portable drives and in the case of certain products <a href="http://www.endpointprotector.com/en/index.php/products/product_overview" target="_blank">it actually allows the creation of file lists</a>, granting access to only those that are safe for use.</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2010/08/18/montefiore-medical-center-data-theft/" rel="bookmark" class="crp_title">Montefiore Medical Center: two computer thefts expose well over 23,000 private records</a></li><li><a href="http://www.endpoint-security.info/2010/03/15/denmark-storage-media-with-9500-private-records-accidentally-exposed/" rel="bookmark" class="crp_title">Denmark: Storage media with 9500 private records accidentally exposed</a></li><li><a href="http://www.endpoint-security.info/2010/07/29/lost-thumb-drive-security-breach/" rel="bookmark" class="crp_title">Lost thumb drive leads to potential data breach</a></li><li><a href="http://www.endpoint-security.info/2011/08/26/access-to-company-data-why-employees-are-not-all-equal/" rel="bookmark" class="crp_title">Access to Company Data: Why Employees Are Not All Equal</a></li><li><a href="http://www.endpoint-security.info/2011/12/18/security-audit-reveals-department-of-taxation-internal-breaches/" rel="bookmark" class="crp_title">Security audit reveals Department of Taxation internal breaches</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2011/06/29/employee-goe-home-with-9000-records-of-coworkers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

