<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Endpoint Security Info &#187; data leak</title>
	<atom:link href="http://www.endpoint-security.info/tag/data-leak/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.endpoint-security.info</link>
	<description>Endpoint Security in the News. Learn to protect your data by controlling removable storage devices.</description>
	<lastBuildDate>Thu, 29 Jul 2010 19:55:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>DoD can&#8217;t handle inside threats</title>
		<link>http://www.endpoint-security.info/2009/05/20/dod-cant-handle-inside-threats/</link>
		<comments>http://www.endpoint-security.info/2009/05/20/dod-cant-handle-inside-threats/#comments</comments>
		<pubDate>Wed, 20 May 2009 12:33:13 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[data leak]]></category>
		<category><![CDATA[espionage]]></category>
		<category><![CDATA[IT security]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=200</guid>
		<description><![CDATA[The Department of Defense seems to have quite some trouble handling threats in his own backyard. One of their officials with top-secret security clearance, as it happens, has allegedly been leaking classified department data and documents to an official working for the Chinese government. According to a Department of Justice announcement quoted by Dark Reading,  [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F05%2F20%2Fdod-cant-handle-inside-threats%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F05%2F20%2Fdod-cant-handle-inside-threats%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>The Department of Defense seems to have quite some trouble handling threats in his own backyard. One of their officials with top-secret security clearance, as it happens, has allegedly been leaking classified department data and documents to an official working for the Chinese government.</p>
<p>According to a <a href="http://www.usdoj.gov/opa/pr/2009/May/09-nsd-469.html" target="new">Department of Justice announcement</a> quoted by <a title="Inside theft from DoD" href="http://www.darkreading.com/insiderthreat/security/government/showArticle.jhtml?articleID=217500189&amp;cid=RSSfeed" target="_blank">Dark Reading</a>,  James Wilbur Fondren Jr., deputy director for the U.S. Pacific Command (PACOM) Washington Liaison Office, has been charged with espionage conspiracy for providing classified information to an agent of a foreign government. Fondren is believed to have sold information to a Taiwanese-American man. The information was subsequently sold to a Chinese government official, but apparently Fondren was unaware of this secon sale.</p>
<p>How was the leak possible? Poor security: Fondren had both a classified DoD computer and an unclassified one on his desk. One would expect a little less trust in high level clearance staff. It&#8217;s espionage we&#8217;re talking about!</p>
<p><a href="http://www.endpointprotector.com/lp/endpoint_protector_general_EN.html" target="_blank"><img style="Endpoint Protector" title="banner-magenta-epp.jpg" src="/wp-content/uploads/banners/banner-magenta-epp.jpg" border="0" alt="banner-magenta-epp.jpg" width="500" height="100" align="middle" /></a></p>
<blockquote><p>Fondren, 62, allegedly funneled the data to Tai Shen Kuo, who was one of his consulting clients, between November 2004 to Feb. 11, 2008, according to the affidavit. Kuo purchased reports from Fondren for anywhere between $350 to $800, eight of which included classified information. Among the classified data Fondren supplied Kuo was information about a joint U.S.-China naval exercise, U.S.-China military meetings, and a DoD draft report on China.</p></blockquote>
<p>In his turn, Kuo got around 50,000 US dollars for certain documents he obtained from Fondren and other DoD officials. I wonder who the other officials are. Will they be charged soon?</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2008/02/05/usb-with-nato-sensitive-data-found-in-swedish-library/" rel="bookmark" class="crp_title">USB with NATO Sensitive Data Found in Swedish Library</a></li><li><a href="http://www.endpoint-security.info/2009/03/06/petty-officer-stole-military-secrets-on-a-usb-stick/" rel="bookmark" class="crp_title">Romanian Petty officer stole military secrets on a USB stick</a></li><li><a href="http://www.endpoint-security.info/2009/07/16/oops-i-accidently-copied-the-goldman-sachs-secret-sauce/" rel="bookmark" class="crp_title">Oops, I accidently copied the Goldman Sachs &#8220;secret sauce&#8221;!</a></li><li><a href="http://www.endpoint-security.info/2009/08/18/uk-defense-experiences-fourfold-rise-in-data-breaches/" rel="bookmark" class="crp_title">UK Defense experiences fourfold rise in data breaches</a></li><li><a href="http://www.endpoint-security.info/2008/03/04/us-government-agencies-have-higher-security-levels/" rel="bookmark" class="crp_title">US Government Agencies Have Higher Security Levels</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2009/05/20/dod-cant-handle-inside-threats/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Possible Insider Leak: 10,000 Patient Records</title>
		<link>http://www.endpoint-security.info/2009/05/18/possible-insider-leak-10000-patient-records/</link>
		<comments>http://www.endpoint-security.info/2009/05/18/possible-insider-leak-10000-patient-records/#comments</comments>
		<pubDate>Mon, 18 May 2009 14:49:10 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[Data Theft & Loss]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[data breack]]></category>
		<category><![CDATA[data leak]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[insider threat]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=199</guid>
		<description><![CDATA[Over 30 reports of data theft filed since January 2009 have lead investigators to a potential leak at Johns Hopkins Hospital. One of their employees is believed to have used her credentials to access and then leak data on more than 10,000 patients while working at the hospital. Law enforcement agencies also suspect that the [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F05%2F18%2Fpossible-insider-leak-10000-patient-records%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2009%2F05%2F18%2Fpossible-insider-leak-10000-patient-records%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>Over 30 reports of data theft filed since January 2009 have lead investigators to a potential leak at Johns Hopkins Hospital. One of their employees is believed to have used her credentials to access and then leak data on more than 10,000 patients while working at the hospital. Law enforcement agencies also suspect that the thefts might be related to a fraudulent driver&#8217;s license scheme discovered in Virginia.</p>
<p><a href="http://www.darkreading.com/insiderthreat/security/privacy/showArticle.jhtml?articleID=217400831&amp;cid=RSSfeed" target="_blank">According to Dark Reading</a>, Johns Hopkins representatives stressed the fact that the data leak was not a hacking incident, but that the suspected employee had access to the breached records as part of her job. They also stated the records contain no medical data, but do contain other sensitive details, such as Social Security numbers and addresses. <a href="http://www.darkreading.com/insiderthreat/security/privacy/showArticle.jhtml?articleID=217400831&amp;cid=RSSfeed">As the Dark Reading article further explained</a>, the hospital took comprehensive measures to balance the loss of data:</p>
<blockquote><p>Johns Hopkins is offering credit monitoring and fraud resolution services, as well as $30,000 in identity theft reimbursements, to the 31 victims, as well as to any of the 526 Virginia residents in the database who report fraud. It also is notifying the other 10,000 patients whose records were in the database.</p></blockquote>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2008/05/04/88000-patients-exposed-to-identity-theft/" rel="bookmark" class="crp_title">88,000 Patients Exposed to Identity Theft</a></li><li><a href="http://www.endpoint-security.info/2008/06/05/the-army-investigates-breach-exposing-1000-to-identity-theft/" rel="bookmark" class="crp_title">The Army Investigates Breach Exposing 1,000 to Identity Theft</a></li><li><a href="http://www.endpoint-security.info/2009/02/20/dark-reading-startd-educational-series/" rel="bookmark" class="crp_title">Dark Reading Starts Educational Series</a></li><li><a href="http://www.endpoint-security.info/2008/05/20/hospitals-a-danger-to-your-personal-data/" rel="bookmark" class="crp_title">Hospitals, a Danger to Your Personal Data</a></li><li><a href="http://www.endpoint-security.info/2009/02/21/faa-data-breach-exposes-records-of-45000/" rel="bookmark" class="crp_title">FAA Data Breach Exposes Records of 45,000</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2009/05/18/possible-insider-leak-10000-patient-records/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Two arrested in BNP data breach case</title>
		<link>http://www.endpoint-security.info/2008/12/09/two-arrested-in-bnp-data-breach-case/</link>
		<comments>http://www.endpoint-security.info/2008/12/09/two-arrested-in-bnp-data-breach-case/#comments</comments>
		<pubDate>Tue, 09 Dec 2008 09:47:30 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[DLP]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[BNP]]></category>
		<category><![CDATA[data leak]]></category>
		<category><![CDATA[Data Loss]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[membership list]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=178</guid>
		<description><![CDATA[The British National Party (BNP) members&#8217; list was posted online in mid November, causing quite a hassle for those exposed, especially since some of them were required by their job descriptions to have no political affiliation. Apparently, a Nottinghamsire pair is responsible for the leak and they are currently in the custody of the Welsh. [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2008%2F12%2F09%2Ftwo-arrested-in-bnp-data-breach-case%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2008%2F12%2F09%2Ftwo-arrested-in-bnp-data-breach-case%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>The British National Party (BNP) members&#8217; list <a title="BNP Data Leak" href="http://www.endpoint-security.info/2008/11/21/british-party-membership-list-gets-posted-online/" target="_blank">was posted online in mid November</a>, causing quite a hassle for those exposed, especially since some of them were required by their job descriptions to have no political affiliation.</p>
<p>Apparently, a Nottinghamsire pair is responsible for the leak and they are currently in the custody of the Welsh. <a title="Arrests in BNP LIst Leak" href="http://www.theregister.co.uk/2008/12/05/bnp_list_arrests/" target="_blank">A Register article quoting the Guardian</a> stated the police said the pair were held in connection with alleged offenses under the UK Data Protection Act.</p>
<blockquote><p>&#8220;We can confirm that last night Nottinghamshire police arrested two people as part of a joint investigation with Dyfed Powys police and the information commissioner&#8217;s office in conjunction with alleged criminal offences under the Data Protection Act,&#8221; a Dyfed Powys police spokesman told The Guardian.</p></blockquote>
<p>The investigation was lead by the Welsh police in collaboration with the information commissioner&#8217;s office. What I would like to know now is if those who were about to lose their jobs because of this data breach will actually be fired. Or will it all be let to rest?</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2008/11/21/british-party-membership-list-gets-posted-online/" rel="bookmark" class="crp_title">British party membership list gets posted online</a></li><li><a href="http://www.endpoint-security.info/2010/05/28/edmonton-credit-card-fraud/" rel="bookmark" class="crp_title">Edmonton travel agency investigated for credit card fraud</a></li><li><a href="http://www.endpoint-security.info/2010/04/14/customer-forms-in-dumpster/" rel="bookmark" class="crp_title">Customer forms thrown in the dumpster</a></li><li><a href="http://www.endpoint-security.info/2008/09/23/2-plead-guilty-in-tjx-hack-case/" rel="bookmark" class="crp_title">2 Plead Guilty in TJX Hack Case</a></li><li><a href="http://www.endpoint-security.info/2009/12/14/french-authorities-use-stolen-data/" rel="bookmark" class="crp_title">Everyone loves stolen data, even the French authorities!</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2008/12/09/two-arrested-in-bnp-data-breach-case/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>British party membership list gets posted online</title>
		<link>http://www.endpoint-security.info/2008/11/21/british-party-membership-list-gets-posted-online/</link>
		<comments>http://www.endpoint-security.info/2008/11/21/british-party-membership-list-gets-posted-online/#comments</comments>
		<pubDate>Fri, 21 Nov 2008 13:19:51 +0000</pubDate>
		<dc:creator>Agent Smith</dc:creator>
				<category><![CDATA[In The Spotlight]]></category>
		<category><![CDATA[security breach]]></category>
		<category><![CDATA[BNP]]></category>
		<category><![CDATA[data leak]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[online fraud]]></category>
		<category><![CDATA[party]]></category>
		<category><![CDATA[UK]]></category>

		<guid isPermaLink="false">http://www.endpoint-security.info/?p=172</guid>
		<description><![CDATA[If you are British and have been plotting to stalk a member of the British National Party (BNP) you might just have missed the opportunity. A list with all the party&#8217;s members, including names, addresses, and email addresses has recently shown up online. Some of those who just got exposed online are also underage (an [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.endpoint-security.info%2F2008%2F11%2F21%2Fbritish-party-membership-list-gets-posted-online%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.endpoint-security.info%2F2008%2F11%2F21%2Fbritish-party-membership-list-gets-posted-online%2F&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>If you are British and have been plotting to stalk a member of the British National Party (BNP) you might just have missed the opportunity. A list with all the party&#8217;s members, including names, addresses, and email addresses has recently shown up online.  Some of those who just got exposed online are also underage (an extra &#8220;benefit&#8221; of the family plan BNP offers) and others had mentions of other personal details made public, such as job or hobbies.</p>
<p>As <a title="BNP looses list" href="http://www.theregister.co.uk/2008/11/18/bnp_loses_list/" target="_blank">the Register</a> puts it, &#8220;That&#8217;s how we know that that BNP members include receptionists, district nurses, amateur historians, pagans, line dancers and a male witch.&#8221; Members reacted pretty strongly, filing their comments with courses and outrage. As certain professions in the UK are expected to have no political color, they might even lose their job and according to several blog sources, some pretty powerful people in the BNP are to blame for the leak.</p>
<p>BNP spokespersons found out of the leak from the Register, but although completely unaware, they promised to treat whoever is responsible quite harshly!</p>
<div id="crp_related"><h3>Related Posts:</h3><ul><li><a href="http://www.endpoint-security.info/2008/12/09/two-arrested-in-bnp-data-breach-case/" rel="bookmark" class="crp_title">Two arrested in BNP data breach case</a></li><li><a href="http://www.endpoint-security.info/2009/04/02/dark-side-of-google-payment-card-details-of-19000-brits-found-in-cache/" rel="bookmark" class="crp_title">Dark Side of Google: Payment card details of 19,000 Brits found in cache</a></li><li><a href="http://www.endpoint-security.info/2008/06/24/anti-fraud-collaborative-service-launches-in-the-us/" rel="bookmark" class="crp_title">Anti-Fraud Collaborative Service Launches in the US</a></li><li><a href="http://www.endpoint-security.info/2010/05/17/la-firemens-cu-potential-breach/" rel="bookmark" class="crp_title">LA Firemen&#8217;s Credit Union notifies 28,000 of potential breach</a></li><li><a href="http://www.endpoint-security.info/2009/12/14/french-authorities-use-stolen-data/" rel="bookmark" class="crp_title">Everyone loves stolen data, even the French authorities!</a></li></ul></div>]]></content:encoded>
			<wfw:commentRss>http://www.endpoint-security.info/2008/11/21/british-party-membership-list-gets-posted-online/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
