<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Privacy Maven &#187; Data Breaches</title>
	<atom:link href="http://www.privacymaven.com/category/data-breaches/feed" rel="self" type="application/rss+xml" />
	<link>http://www.privacymaven.com</link>
	<description>Privacy, Security, and Preservation of Integrity, Liberty, Freedom and Civility</description>
	<lastBuildDate>Mon, 19 Jul 2010 02:19:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Nonpartisan Snooping?  Passport Breach Hits All 3 Presidential Candidates</title>
		<link>http://www.privacymaven.com/nonpartisan-snooping-passport-breach-hits-all-3-presidential-candidates.html</link>
		<comments>http://www.privacymaven.com/nonpartisan-snooping-passport-breach-hits-all-3-presidential-candidates.html#comments</comments>
		<pubDate>Fri, 21 Mar 2008 23:02:08 +0000</pubDate>
		<dc:creator>Privacy Maven</dc:creator>
				<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Public Figures and Privacy]]></category>

		<guid isPermaLink="false">http://www.privacymaven.com/2008/03/21/nonpartisan-snooping-passport-breach-hits-all-3-presidential-candidates/</guid>
		<description><![CDATA[What&#8217;s a Presidential candidate to do, other than issue statements and demand investigations? The State Department said on Friday that it was investigating several incidents in which the passport files of all three presidential contenders were improperly accessed by employees. The breaches involved electronic files that contained personal information about Senators Barack Obama, Hillary Rodham [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.privacymaven.com%2Fnonpartisan-snooping-passport-breach-hits-all-3-presidential-candidates.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.privacymaven.com%2Fnonpartisan-snooping-passport-breach-hits-all-3-presidential-candidates.html&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>What&#8217;s a Presidential candidate to do, other than<a href="http://www.nytimes.com/2008/03/21/us/politics/21cnd-passport.html?hp"> issue statements and demand investigations</a>?  </p>
<blockquote><p>The State Department said on Friday that it was investigating several incidents in which the passport files of all three presidential contenders were improperly accessed by employees.</p>
<p>The breaches involved electronic files that contained personal information about Senators Barack Obama, Hillary Rodham Clinton and John McCain. A State Department spokesman declined to say what was in those files, but he said they were likely to contain biographical information and passport applications.</p>
<p>Mr. Obama’s passport file was breached on three separate occasions earlier this year and as recently as last week, by three employees working for independent contractors who did not have authorization to access the information. The breaches occurred on Jan. 9, Feb. 21, and March 14, according to The Associated Press.</p>
<p>The State Department’s computer system had flagged each incident, but senior department officials were not informed until they looked into the matter, after receiving inquiries from a reporter on Thursday, a department spokesman said. “That information didn’t rise up to senior management levels,” the spokesman, Sean McCormack, said at a Friday news conference. “That should have happened.”</p>
</blockquote>
<p><span id="more-156"></span></p>
<blockquote>
<p>Two of the employees were fired, Mr. McCormack said. The Associated Press reported that they had worked for Stanley, Inc., a company that provides administrative support and services to government groups and is based in Arlington, Va. Stanley signed a five-year, $570 million contract with the State Department earlier this week to work on the department’s passport database.</p>
<p>The third employee also accessed Mr. McCain’s file, but was only reprimanded and remains employed.</p>
</blockquote>
<p>More updates <a href="http://thecaucus.blogs.nytimes.com/2008/03/21/state-dept-punishes-aides-for-obama-passport-breach/index.html?ref=politics">here</a> and <a href="http://michellemalkin.com/2008/03/21/first-obamas-passportnow-hillarys-breached-too/">here</a>.  Watch several news reports here.<br />
<br />
<object width="425" height="355"><param name="movie" value="http://www.youtube.com/v/BUtUAHLLB6U"></param><param name="wmode" value="transparent"></param><embed src="http://www.youtube.com/v/BUtUAHLLB6U" type="application/x-shockwave-flash" wmode="transparent" width="425" height="355"></embed></object></p>
<p></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.privacymaven.com%2Fnonpartisan-snooping-passport-breach-hits-all-3-presidential-candidates.html';
  addthis_title  = 'Nonpartisan+Snooping%3F++Passport+Breach+Hits+All+3+Presidential+Candidates';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.privacymaven.com/nonpartisan-snooping-passport-breach-hits-all-3-presidential-candidates.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Obama Passport Breach: Rice Apologizes for &#8220;Imprudent Curiosity&#8221; of Her Staff</title>
		<link>http://www.privacymaven.com/obama-passport-breach-rice-apologizes-for-imprudent-curiosity-of-her-staff.html</link>
		<comments>http://www.privacymaven.com/obama-passport-breach-rice-apologizes-for-imprudent-curiosity-of-her-staff.html#comments</comments>
		<pubDate>Fri, 21 Mar 2008 16:16:32 +0000</pubDate>
		<dc:creator>Privacy Maven</dc:creator>
				<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Public Figures and Privacy]]></category>

		<guid isPermaLink="false">http://www.privacymaven.com/2008/03/21/obama-passport-breach-rice-apologizes-for-imprudent-curiosity-of-her-staff/</guid>
		<description><![CDATA[The State Dept. called it &#8220;imprudent curiosity.&#8221; The Obama campaign called it &#8220;an outrageous breach of security and privacy.&#8221; Caught between adjectival phrases, Secretary of State Rice apologized to Senator Barack Obama. More coverage at Hot Air. As the Washington Post reports, Two State Department employees were fired and a third has been disciplined for [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.privacymaven.com%2Fobama-passport-breach-rice-apologizes-for-imprudent-curiosity-of-her-staff.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.privacymaven.com%2Fobama-passport-breach-rice-apologizes-for-imprudent-curiosity-of-her-staff.html&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>The State Dept. <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/03/20/AR2008032003422.html?hpid=topnews">called it &#8220;imprudent curiosity.</a>&#8221;  The Obama campaign called it &#8220;an outrageous breach of security and privacy.&#8221; Caught between adjectival phrases, <a href="http://thecaucus.blogs.nytimes.com/2008/03/20/state-dept-punishes-aides-for-obama-passport-breach/index.html?hp">Secretary of State Rice apologized to Senator Barack Obama</a>.  </p>
<p>
<iframe height="339" width="425" src="http://www.msnbc.msn.com/id/22425001/vp/23743753#23743753" frameborder="0" scrolling="no"></iframe><br />
</p>
<p>More coverage at <a href="http://hotair.com/archives/2008/03/20/state-dept-two-contractors-fired-for-accessing-obamas-passport-records/">Hot Air</a>.  As <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/03/20/AR2008032003422.html?hpid=topnews">the <em>Washington Post</em> reports</a>,</p>
<blockquote><p>Two State Department employees were fired and a third has been disciplined for improperly accessing Sen. Barack Obama&#8217;s passport file, the State Department announced last night.</p>
<p>Senior department officials said they learned of the incidents only when a reporter made an inquiry yesterday afternoon. They said an initial investigation indicated that the employees &#8212; all of whom worked on contract &#8212; were motivated by &#8220;imprudent curiosity.&#8221;
</p></blockquote>
<p><span id="more-155"></span></p>
<blockquote><p>
Bill Burton, spokesman for Obama&#8217;s presidential campaign, called the incidents &#8220;an outrageous breach of security and privacy.&#8221; He said this is &#8220;a serious matter that merits a complete investigation,&#8221; adding that the campaign will &#8220;demand to know who looked at Senator Obama&#8217;s passport file, for what purpose, and why it took so long for them to reveal this security breach.&#8221;</p>
<p>Undersecretary of State Patrick F. Kennedy, in a hastily arranged conference call with reporters, said he asked the State Department inspector general to open an inquiry into the matter and acknowledged that it might need to be expanded.</p>
<p>He also said he would brief Obama, who is locked in a tight race for the Democratic presidential nomination with Sen. Hillary Rodham Clinton, today on the matter.</p>
<p>Kennedy said that he did not know yet whether any laws were broken or whether the employees shared the information with others. He said that the incidents, which occurred at three offices, on Jan. 9, Feb. 21 and March 14, should have been &#8220;passed up the line&#8221; much sooner and that officials were seeking to determine why they had not been disclosed earlier.</p>
<p>Secretary of State Condoleezza Rice, who was briefed yesterday afternoon, requested a &#8220;full investigation,&#8221; department spokesman Sean McCormack said. </p></blockquote>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.privacymaven.com%2Fobama-passport-breach-rice-apologizes-for-imprudent-curiosity-of-her-staff.html';
  addthis_title  = 'Obama+Passport+Breach%3A+Rice+Apologizes+for+%26%238220%3BImprudent+Curiosity%26%238221%3B+of+Her+Staff';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.privacymaven.com/obama-passport-breach-rice-apologizes-for-imprudent-curiosity-of-her-staff.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Facebook Sues Canadian Internet Porn Company for Hacking Attempt</title>
		<link>http://www.privacymaven.com/facebook-sues-canadian-internet-porn-company-for-hacking-attempt.html</link>
		<comments>http://www.privacymaven.com/facebook-sues-canadian-internet-porn-company-for-hacking-attempt.html#comments</comments>
		<pubDate>Mon, 17 Dec 2007 20:27:15 +0000</pubDate>
		<dc:creator>Privacy Maven</dc:creator>
				<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Social Networking]]></category>

		<guid isPermaLink="false">http://www.privacymaven.com/2007/12/17/facebook-sues-canadian-internet-porn-company-for-hacking-attempt/</guid>
		<description><![CDATA[The Toronto Star reports on the massive hacking attempts of Ontario porn company, SlickCash, on Facebook&#8217;s servers. A Canadian company specializing in Internet porn is being sued by Facebook amid allegations it hacked the popular social networking website&#8217;s computers and tried to access the personal information of users, court documents show. A numbered Ontario company, [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.privacymaven.com%2Ffacebook-sues-canadian-internet-porn-company-for-hacking-attempt.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.privacymaven.com%2Ffacebook-sues-canadian-internet-porn-company-for-hacking-attempt.html&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p><em>The Toronto Star</em> reports on the <a href="http://www.thestar.com/article/286091">massive hacking attempts</a> of Ontario porn company, SlickCash, on Facebook&#8217;s servers.</p>
<blockquote><p> A Canadian company specializing in Internet porn is being sued by Facebook amid allegations it hacked the popular social networking website&#8217;s computers and tried to access the personal information of users, court documents show.</p>
<p>A numbered Ontario company, which does business online under the name SlickCash, along with several people in the Toronto area, are named in an amended complaint filed by Facebook in San Jose, Calif.</p>
<p>The hugely popular information sharing website alleges that, for two weeks last June, the defendants attempted to access Facebook&#8217;s servers at least 200,000 times.</p>
<p>&#8220;Each of these requests sought to direct Facebook&#8217;s computers to send information on other Facebook users back to (the company&#8217;s Internet Protocol) address,&#8221; the court documents say.</p>
<p>&#8220;These requests for information from Facebook generated error messages and were detected as unauthorized attempts to access and harvest proprietary information.&#8221;</p>
<p>It wasn&#8217;t clear from the documents what information was accessed, but the complaint alleges &#8220;the defendants knowingly and without permission took, copied, or made use of, data from Facebook&#8217;s proprietary computers and computer network.&#8221;</p>
<p>Facebook, with an estimated 34 million users worldwide, allows members to post photos alongside personal information like a birth date, hometown, e-mail address, phone number, and workplace.</p></blockquote>
<p><a href="http://www.theregister.co.uk/2007/12/17/facebook_hack_attack_lawsuit/">As <em>The Register</em> notes, the lawsuit</a> brings more attention to the vulnerability of members&#8217; data on Facebook.</p>
<blockquote><p>It&#8217;s not terribly clear what data was accessed, much less the goals of the alleged attack. Court papers (<a href="http://docs.justia.com/cases/federal/district-courts/california/candce/5:2007cv03404/193531/17/0.pdf" target="_blank">PDF</a>) allege the defendants uploaded scripted commands to a server run by a firm called Accretive to &#8220;gain unauthorised access and launch malicious code&#8221; on Facebook&#8217;s site.</p>
<p>Facebook encourages users to post personal information such as birth date, hometown, email address, work details and even phone numbers online. This information is shared with a user&#8217;s &#8220;friends&#8221; and, in a lot of cases, other on any network a user cares to join. The social networking utility boasts a membership of 34m users.</p>
<p>Any amount Facebook might hope to gain from this suit is surely outweighed by the damage to its already poor reputation for privacy. More than anything else the lawsuit emphasises that Facebook is an insecure place to post personal information. Since Facebook&#8217;s business model, such as it is, relies of people coughing up this information that&#8217;s hardly a good thing.</p></blockquote>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.privacymaven.com%2Ffacebook-sues-canadian-internet-porn-company-for-hacking-attempt.html';
  addthis_title  = 'Facebook+Sues+Canadian+Internet+Porn+Company+for+Hacking+Attempt';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.privacymaven.com/facebook-sues-canadian-internet-porn-company-for-hacking-attempt.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Salesforce.com Employee Conned By Phisher, Reveals Company Database</title>
		<link>http://www.privacymaven.com/salesforcecom-employee-conned-by-phisher-reveals-company-database.html</link>
		<comments>http://www.privacymaven.com/salesforcecom-employee-conned-by-phisher-reveals-company-database.html#comments</comments>
		<pubDate>Thu, 08 Nov 2007 18:48:43 +0000</pubDate>
		<dc:creator>Privacy Maven</dc:creator>
				<category><![CDATA[Data Breaches]]></category>
		<category><![CDATA[Phishing]]></category>

		<guid isPermaLink="false">http://www.privacymaven.com/2007/11/08/salesforcecom-employee-conned-by-phisher-reveals-company-database/</guid>
		<description><![CDATA[As reported by Information Week: A Salesforce.com employee bit on the bait of a phisher, and now the Web-based CRM software provider is warning customers not to fall for the same cybercriminal tricks. On its Trust.Salesforce.com Web site this week, Salesforce.com posted a &#8220;letter about security&#8221; to customers alerting them to be cautious of &#8220;phishing [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.privacymaven.com%2Fsalesforcecom-employee-conned-by-phisher-reveals-company-database.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.privacymaven.com%2Fsalesforcecom-employee-conned-by-phisher-reveals-company-database.html&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>As reported by <a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=202803560"><em>Information Week</em></a>:</p>
<blockquote><p>A Salesforce.com employee bit on the bait of a phisher, and now the Web-based CRM software provider is warning customers not to fall for the same cybercriminal tricks.</p>
<p>On its Trust.Salesforce.com Web site this week, Salesforce.com posted a &#8220;letter about security&#8221; to customers alerting them to be cautious of &#8220;phishing and malware scams on the Internet,&#8221; which are on &#8220;the rise.&#8221;</p>
<p>In fact, the company revealed that a Salesforce.com employee had been a recent victim of a phishing scam that tricked the worker into disclosing a password, providing the phisher with information on a customer contact list. That contact list information included &#8220;first and last names, company names, e-mail addresses, and telephone numbers for Salesforce.com customers and related administrative data&#8221; belonging to Salesforce.com, according to the letter.</p>
<p>The letter, which was signed by Salesforce.com executive VP Parker Harris, also revealed that &#8220;a small number&#8221; of Salesforce.com customer users subsequently have become victims of a phishing &#8212; being fooled into disclosing passwords after receiving &#8220;bogus e-mails that looked like a Salesforce.com invoice but were not.&#8221;</p>
<p>In addition, &#8220;a few days ago, a new wave of phishing attempts that included attached malware &#8212; software that secretly installs viruses or key loggers &#8212; appeared and seemed to be targeted at a broader group of customers,&#8221; the company disclosed in the notice.</p>
<p>&#8220;That&#8217;s why we warned our system administrators last week of this new, more malicious phish and why we are sending this letter now with the goal of increasing awareness.&#8221;</p></blockquote>
<p>The incident brings to mind that we must all be wary and take precautions.   As always, <em>Privacy Maven</em> recommends the helpful resources of the <a href="http://www.antiphishing.org/">Anti-Phishing Working Group</a> to stay apprised of current phishing scams.</p>
<blockquote></blockquote>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.privacymaven.com%2Fsalesforcecom-employee-conned-by-phisher-reveals-company-database.html';
  addthis_title  = 'Salesforce.com+Employee+Conned+By+Phisher%2C+Reveals+Company+Database';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.privacymaven.com/salesforcecom-employee-conned-by-phisher-reveals-company-database.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TJX Data Breach Affected 94 Million Customers, Possibly the Largest Data Breach in History</title>
		<link>http://www.privacymaven.com/tjx-data-breach-affected-94-million-customers-possibly-the-largest-data-breach-in-history.html</link>
		<comments>http://www.privacymaven.com/tjx-data-breach-affected-94-million-customers-possibly-the-largest-data-breach-in-history.html#comments</comments>
		<pubDate>Sun, 28 Oct 2007 00:39:13 +0000</pubDate>
		<dc:creator>Privacy Maven</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.privacymaven.com/2007/10/27/tjx-data-breach-affected-94-million-customers-possibly-the-largest-data-breach-in-history/</guid>
		<description><![CDATA[Consumer Affairs reports on details emerging: New information from a lawsuit against the TJX Corporation over its breach of customer information revealed that as many as 94 million Visa and Mastercard holders were exposed to hackers. The new number was nearly double the initial estimate of 46 million affected customers that TJX reported in early [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.privacymaven.com%2Ftjx-data-breach-affected-94-million-customers-possibly-the-largest-data-breach-in-history.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.privacymaven.com%2Ftjx-data-breach-affected-94-million-customers-possibly-the-largest-data-breach-in-history.html&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.consumeraffairs.com/news04/2007/10/tjx_data.html">Consumer Affairs reports</a> on details emerging:</p>
<blockquote><p> New information from a lawsuit against the TJX <a href="http://www.consumeraffairs.com/news04/2007/10/tjx_data.html#" id="KonaLink0" target="_top" class="kLink" style="text-decoration: underline ! important; position: static"><font style="color: red ! important; font-family: 'Book Antiqua','Times New Roman','CG Times',serif; font-weight: 400; font-size: 14.6667px; position: static" color="red"><span class="kLink" style="border-bottom: 1px solid red; color: red ! important; font-family: 'Book Antiqua','Times New Roman','CG Times',serif; font-weight: 400; font-size: 14.6667px; position: static; padding-bottom: 1px; background-color: transparent"></span></font></a>Corporation over its breach of customer information revealed that as many as 94 million Visa and Mastercard holders were exposed to hackers.</p>
<p>The new number was nearly double the initial estimate of <a href="http://www.consumeraffairs.com/news04/2007/03/tjx_biggest_ever.html">46 million affected customers</a> that TJX reported in early 2007, when the breach was first revealed.</p>
<p>Visa officials estimated losses of $65 million to $83 million as a result of the breach, the largest and most exact number provided yet. The new information may officially mark the TJX affair as the <a href="http://www.consumeraffairs.com/news04/2007/03/tjx_biggest_ever.html">biggest data breach in history.</a></p>
<p>The information came as part of a lawsuit filed by a coalition of banks against TJX, whom the banks hold responsible for not securing and protecting cardholders&#8217; data as they performed transactions and made purchases.</p></blockquote>
<p><img src="http://www.privacymaven.com/images/tjx.jpg" title="TJX" alt="TJX" align="middle" height="250" width="382" /></p>
<p>The extent of the security lapse at TJX is staggering.   <a href="http://www.eweek.com/article2/0,1895,2207781,00.asp">eWeek reports</a> on what has been uncovered thus far:</p>
<blockquote><p> Citing new information about the TJX data breach, attorneys suing the clothing retail chain amended their complaints on Oct. 25 and want a jury to evaluate TJX&#8217;s security professionalism.</p>
<p>New details that emerged from documents filed in federal court Oct. 25 include:<br />
# A TJX consultant found that not only was TJX not PCI-compliant, but it had failed to comply with nine of the 12 applicable PCI requirements. Many were &#8220;high-level deficiencies,&#8221; the consultant said.</p>
<p># &#8220;After locating the stored data on the TJX servers, the intruder used the TJX high-speed connection in Massachusetts to transfer this data to another site on the Internet&#8221; in California. More than &#8220;80 GBytes of stored data improperly retained by TJX were transferred in this manner. TJX did not detect this transfer.&#8221;</p>
<p># In May 2006, a traffic capture/sniffer program was installed on the TJX network by the cyber-thieves, where it remained undetected for seven months, &#8220;capturing sensitive cardholder data as it was transmitted in the clear by TJX.&#8221;</p>
<p># In 2004, before the attacks began, TJX was issued a report on its security compliance that &#8220;identified numerous serious deficiencies at TJX, including specific violations. TJX did not remedy many of these deficiencies.&#8221;</p></blockquote>
<p>Read the rest of <a href="http://www.eweek.com/article2/0,1895,2207781,00.asp">the article</a> for more details and links to previous coverage of the TJX data breach.<br />
<br />
<a href="http://www.kqzyfj.com/click-2567372-10437588" target="_top"><br />
<img src="http://www.tqlkg.com/image-2567372-10437588" width="180" height="150" alt="LifeLock Identity Theft Prevention - Save 10% " border="0"/></a><br /></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.privacymaven.com%2Ftjx-data-breach-affected-94-million-customers-possibly-the-largest-data-breach-in-history.html';
  addthis_title  = 'TJX+Data+Breach+Affected+94+Million+Customers%2C+Possibly+the+Largest+Data+Breach+in+History';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.privacymaven.com/tjx-data-breach-affected-94-million-customers-possibly-the-largest-data-breach-in-history.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Not Your Average Joe&#8217;s Restaurant Chain Reports Data Breach</title>
		<link>http://www.privacymaven.com/not-your-average-joes-restaurant-chain-reports-data-breach.html</link>
		<comments>http://www.privacymaven.com/not-your-average-joes-restaurant-chain-reports-data-breach.html#comments</comments>
		<pubDate>Wed, 24 Oct 2007 16:37:02 +0000</pubDate>
		<dc:creator>Privacy Maven</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.privacymaven.com/2007/10/24/not-your-average-joes-restaurant-chain-reports-data-breach/</guid>
		<description><![CDATA[According to The Boston Globe: Not Your Average Joe&#8217;s, a Massachusetts restaurant chain, said yesterday that thieves have stolen credit card data belonging to its customers. The Dartmouth-based chain estimated less than 3,500 of the 350,000 customers it served in August and September had their credit card information stolen. The 14-restaurant chain said it is [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.privacymaven.com%2Fnot-your-average-joes-restaurant-chain-reports-data-breach.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.privacymaven.com%2Fnot-your-average-joes-restaurant-chain-reports-data-breach.html&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>According to <a href="http://www.boston.com/business/globe/articles/2007/10/24/restaurant_chain_customers_credit_card_data_stolen/"><em>The Boston Globe</em></a>:</p>
<blockquote><p>Not Your Average Joe&#8217;s, a Massachusetts restaurant chain, said yesterday that thieves have stolen credit card data belonging to its customers.</p>
<p>The Dartmouth-based chain estimated less than 3,500 of the 350,000 customers it served in August and September had their credit card information stolen. The 14-restaurant chain said it is working with the US Secret Service and major credit card companies to determine how the data theft occurred and precisely how many customers were affected.</p>
<p>Today, the chain plans to post on its website a notice to customers about the security breach.</p></blockquote>
<p>
<a href="http://www.kqzyfj.com/click-2567372-10437588" target="_top"><br />
<img src="http://www.tqlkg.com/image-2567372-10437588" width="180" height="150" alt="LifeLock Identity Theft Prevention - Save 10% " border="0"/></a><br /></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.privacymaven.com%2Fnot-your-average-joes-restaurant-chain-reports-data-breach.html';
  addthis_title  = 'Not+Your+Average+Joe%26%238217%3Bs+Restaurant+Chain+Reports+Data+Breach';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.privacymaven.com/not-your-average-joes-restaurant-chain-reports-data-breach.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Gap Laptop Theft Puts 800,000 Job Applicants&#8217; Identities At Risk</title>
		<link>http://www.privacymaven.com/gap-laptop-theft-puts-800000-job-applicants-identities-at-risk.html</link>
		<comments>http://www.privacymaven.com/gap-laptop-theft-puts-800000-job-applicants-identities-at-risk.html#comments</comments>
		<pubDate>Tue, 02 Oct 2007 17:13:34 +0000</pubDate>
		<dc:creator>Privacy Maven</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.privacymaven.com/2007/10/02/gap-laptop-theft-puts-800000-job-applicants-identities-at-risk/</guid>
		<description><![CDATA[A laptop has been stolen from a vendor that manages the job applications for Gap, Inc., putting the personal information of 800,000 job applicants at risk. A statement has been posted on the Gap website: Gap Inc. (NYSE: GPS) today announced that a laptop containing the personal information of certain job applicants was recently stolen [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.privacymaven.com%2Fgap-laptop-theft-puts-800000-job-applicants-identities-at-risk.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.privacymaven.com%2Fgap-laptop-theft-puts-800000-job-applicants-identities-at-risk.html&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>A laptop has been stolen from a vendor that manages the job applications for Gap, Inc., putting the personal information of 800,000 job applicants at risk.  <a href="http://www.gapinc.com/public/Media/Press_Releases/med_pr_092807announcement.shtml">A statement</a> has been posted on the Gap website:</p>
<blockquote><p>Gap Inc. (NYSE: GPS) today  announced that a laptop containing the personal information of certain job  applicants was recently stolen from the offices of an experienced third-party  vendor that manages job applicant data for Gap Inc.</p>
<p>The company has begun notifying the job applicants whose Social Security  numbers were included in the information on the laptop and is offering them a  year of free credit monitoring services with fraud resolution assistance,  along with a dedicated 24-hour helpline.</p>
<p>Personal data for approximately 800,000 people who applied online or by phone  for store positions at one of Gap Inc.’s brands between July 2006 and June  2007 was contained on the stolen laptop. Contrary to the company’s agreement  with the vendor, the information on the laptop was not encrypted. The company  has no reason to believe the data contained on the computer was the target of  the theft or that the personal information has been accessed or used  improperly.</p>
<p>“Gap Inc. deeply regrets this incident occurred. We take our obligation to  protect the data security of personal information very seriously,” said Gap  Inc. Chairman and CEO Glenn Murphy. “What happened here is against everything  we stand for as a company. We’re reviewing the facts and circumstances that  led to this incident closely, and will take appropriate steps to help prevent  something like this from happening again.”</p></blockquote>
<p style="text-align: center"><img src="http://www.privacymaven.com/images/gap.jpg" title="The Gap" alt="The Gap" height="233" width="448" /></p>
<p><a href="http://www.consumeraffairs.com/news04/2007/10/gap_data.html">Consumer Affairs discusses the implications</a> and consequences of such outsourcing:</p>
<blockquote><p>Outsourcing of <a href="http://www.consumeraffairs.com/news04/2007/10/gap_data.html#" id="KonaLink2" target="_top" class="kLink" style="text-decoration: underline ! important; position: static"><font style="color: red ! important; font-family: 'Book Antiqua','Times New Roman','CG Times',serif; font-weight: 400; font-size: 14.6667px; position: static" color="red"><span class="kLink" style="border-bottom: 1px solid red; color: red ! important; font-family: 'Book Antiqua','Times New Roman','CG Times',serif; font-weight: 400; font-size: 14.6667px; position: static; padding-bottom: 1px; background-color: transparent"></span></font></a>business processes such as billing, payroll, and employee data to third parties has been a primary cause of data breaches in recent years. Third-party companies that handle personal data often do not adhere to the privacy standards of the companies or government agencies they are contracted to, and simply passing data through multiple hands increases the risk that it may be lost, stolen, or misused.</p></blockquote>
<p>
<a href="http://www.dpbolvw.net/click-2567372-10437585" target="_top"><br />
<img src="http://www.ftjcfx.com/image-2567372-10437585" width="150" height="50" alt="LifeLock Identity Theft Prevention - Save 10% " border="0"/></a><br /></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.privacymaven.com%2Fgap-laptop-theft-puts-800000-job-applicants-identities-at-risk.html';
  addthis_title  = 'Gap+Laptop+Theft+Puts+800%2C000+Job+Applicants%26%238217%3B+Identities+At+Risk';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.privacymaven.com/gap-laptop-theft-puts-800000-job-applicants-identities-at-risk.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TJX Offers Settlement in Aftermath of World&#8217;s Largest Data Breach</title>
		<link>http://www.privacymaven.com/tjx-offers-settlement-in-aftermath-of-worlds-largest-data-breach.html</link>
		<comments>http://www.privacymaven.com/tjx-offers-settlement-in-aftermath-of-worlds-largest-data-breach.html#comments</comments>
		<pubDate>Wed, 26 Sep 2007 17:02:15 +0000</pubDate>
		<dc:creator>Privacy Maven</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.privacymaven.com/2007/09/26/tjx-offers-settlement-in-aftermath-of-worlds-largest-data-breach/</guid>
		<description><![CDATA[TJX is offering settlement terms: In an attempt to reach a settlement with customers over a massive data breach, TJX Companies is offering to reimburse people for the cost of replacing their driver&#8217;s licenses, three years of credit monitoring, and three-day, 15%-off sale. The company announced the plan in an online advisory, noting that it&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.privacymaven.com%2Ftjx-offers-settlement-in-aftermath-of-worlds-largest-data-breach.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.privacymaven.com%2Ftjx-offers-settlement-in-aftermath-of-worlds-largest-data-breach.html&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.informationweek.com/security/showArticle.jhtml?articleID=202101077">TJX is offering settlement </a>terms:</p>
<blockquote><p><span id="articleBody"> In an attempt to reach a settlement with customers over a massive data breach, TJX Companies is offering to reimburse people for the cost of replacing their driver&#8217;s licenses, three years of credit monitoring, and three-day, 15%-off sale. The company announced the plan in <a href="http://www.tjx.com/index.html">an online advisory</a>, noting that it&#8217;s subject to court approval.</span></p>
<p>TJX, which is the parent company of retailers such as T.J. Maxx, Marshalls, and HomeGoods, announced early this year the <a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=199203277">loss of more than 45 million credit and debit card numbers</a> that were stolen from its IT systems over an 18-month period. It&#8217;s considered to be the largest customer data breach on record.</p>
<p>In August, the company <a href="http://www.informationweek.com/security/showArticle.jhtml?articleID=201800259&amp;subSection=">reported in its second-quarter earnings</a> that the company had to absorb a $118 million charge related to the massive security breach. For the second quarter, which ended July 28, the breach cost 25 cents per share &#8212; 10 times more than the 2 cents to 3 cents per share company executives estimated just three months ago.</p></blockquote>
<p><img src="http://www.privacymaven.com/images/tjmaxx.jpg" title="TJ Maxx" alt="TJ Maxx" align="middle" height="346" width="300" /></p>
<p align="left">The Motley Fool considers this a &#8220;<a href="http://www.fool.com/personal-finance/general/2007/09/25/tjs-crafty-settlement.aspx">crafty settlement</a>:&#8221;</p>
<blockquote>
<p align="left">TJX&#8217;s settlement includes two interesting features. For customers that shopped at TJX department stores during the affected period, the company is offering vouchers to cover &#8220;costs as a result of the intrusion.&#8221; The vouchers are good for use at local TJX stores. As you might guess, a relatively small denomination voucher is a great way to get shoppers into a store and potentially spend more than the value of the voucher. Another piece of the settlement is a future event at TJX stores that will give across-the-board savings of 15%. Far from a specific &#8220;result of the intrusion&#8221; event, this sale will be open to all customers.</p>
</blockquote>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.privacymaven.com%2Ftjx-offers-settlement-in-aftermath-of-worlds-largest-data-breach.html';
  addthis_title  = 'TJX+Offers+Settlement+in+Aftermath+of+World%26%238217%3Bs+Largest+Data+Breach';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.privacymaven.com/tjx-offers-settlement-in-aftermath-of-worlds-largest-data-breach.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GAO Asserts VA Is at Risk for Another Data Breach</title>
		<link>http://www.privacymaven.com/gao-asserts-va-is-at-risk-for-another-data-breach.html</link>
		<comments>http://www.privacymaven.com/gao-asserts-va-is-at-risk-for-another-data-breach.html#comments</comments>
		<pubDate>Fri, 21 Sep 2007 18:44:47 +0000</pubDate>
		<dc:creator>Privacy Maven</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.privacymaven.com/2007/09/21/gao-asserts-va-is-at-risk-for-another-data-breach/</guid>
		<description><![CDATA[In May, 2006, the Veterans Administration (VA) fell victim to an enormous data breach, affecting more than 26.5 million veterans. Now more than a year later, the news from the Government Accounting Office (GAO) is not good. They assess that the VA is at risk for another data breach: A GAO audit of physical controls [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.privacymaven.com%2Fgao-asserts-va-is-at-risk-for-another-data-breach.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.privacymaven.com%2Fgao-asserts-va-is-at-risk-for-another-data-breach.html&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>In May, 2006, the <a href="http://www.internetnews.com/bus-news/article.php/3608411">Veterans Administration (VA) fell victim to an enormous data breach</a>, affecting more than 26.5 million veterans.  Now more than a year later, the news from the Government Accounting Office (GAO) is not good.  They assess that the <a href="http://www.scmagazineus.com/GAO-VA-at-risk-of-another-data-breach/article/35765/">VA is at risk for another data breach</a>:</p>
<blockquote><p>A GAO audit of physical controls at VA installations found more than 100 missing IT-related items, according to a report by government investigators released this week.</p>
<p class="MsoNormal">The VA <a href="http://www.scmagazineus.com/Infamous-VA-laptop-recovered-appears-not-to-have-been-tampered-with/article/33575/">suffered a massive data breach</a> last May when a laptop was stolen from the Aspen Hill, Va., home of a department employee. The incident affected 26.5 million veterans and active-duty members of the U.S. Armed Forces.<o:p><br />
</o:p></p>
<p class="MsoNormal">The theft of any one of 53 missing computers noted by the GAO could result in another breach, according to the agency.<o:p></o:p></p>
<p><o:p> 				</o:p>“Our assessment found that a weak overall control environment for IT equipment at the four locations we audited posed a significant security vulnerability to the nation&#8217;s veterans with regard to sensitive data maintained on this equipment,” Valerie C. Melvin, director of human capital and management information systems issues at the GAO, testified before the U.S. Senate Committee on Veterans Affairs on Wednesday. “Our statistical tests of physical inventory controls at the four locations identified a total of 123 missing IT equipment items, including 53 computers that could have stored sensitive data. The lack of user-level accountability and inaccurate records on status, location and item descriptions make it difficult to determine the extent to which actual theft, loss or misappropriation may have occurred without detection.”</p></blockquote>
<p>As with last year&#8217;s incident, veterans are left to fend for themselves.  It underscores the importance for all of us to be vigilant over our financial and personal records.  There are several useful resources on the Internet, including the government website <a href="http://www.idtheft.gov">IDTheft.gov</a> and <a href="http://www.privacyrights.org/fs/fs17-it.htm">Privacy Rights Clearinghouse</a>.<br />
<br />
<a href="http://www.dpbolvw.net/click-2567372-10437585" target="_top"><br />
<img src="http://www.ftjcfx.com/image-2567372-10437585" width="150" height="50" alt="LifeLock Identity Theft Prevention - Save 10% " border="0"/></a><br /></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.privacymaven.com%2Fgao-asserts-va-is-at-risk-for-another-data-breach.html';
  addthis_title  = 'GAO+Asserts+VA+Is+at+Risk+for+Another+Data+Breach';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.privacymaven.com/gao-asserts-va-is-at-risk-for-another-data-breach.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TD Ameritrade May Have Known of Data Breach a Year Ago</title>
		<link>http://www.privacymaven.com/td-ameritrade-may-have-known-of-data-breach-a-year-ago.html</link>
		<comments>http://www.privacymaven.com/td-ameritrade-may-have-known-of-data-breach-a-year-ago.html#comments</comments>
		<pubDate>Tue, 18 Sep 2007 16:15:03 +0000</pubDate>
		<dc:creator>Privacy Maven</dc:creator>
				<category><![CDATA[Data Breaches]]></category>

		<guid isPermaLink="false">http://www.privacymaven.com/2007/09/18/td-ameritrade-may-have-known-of-data-breach-a-year-ago/</guid>
		<description><![CDATA[In recent days, more and more worrisome details are emerging regarding the data breach at TD Ameritrade which has affected its 6.3 million customers. Initial reports were slim on detail, as evidenced in this brief CNN news report. Now Information Week reports: An attorney launching a class-action lawsuit against TD Ameritrade Holding alleges the online [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.privacymaven.com%2Ftd-ameritrade-may-have-known-of-data-breach-a-year-ago.html"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.privacymaven.com%2Ftd-ameritrade-may-have-known-of-data-breach-a-year-ago.html&amp;style=normal" height="61" width="50" /><br />
			</a>
		</div>
<p>In recent days, more and more worrisome details are emerging regarding the <a href="http://www.informationweek.com/blog/main/archives/2007/09/ameritrade_noti.html">data breach at TD Ameritrade</a> which has affected its 6.3 million customers.  Initial reports were slim on detail, as evidenced in this brief CNN news report.</p>
<p><object width="425" height="350"><param name="movie" value="http://www.youtube.com/v/8B4-CE5cvN8"></param><param name="wmode" value="transparent"></param><embed src="http://www.youtube.com/v/8B4-CE5cvN8" type="application/x-shockwave-flash" wmode="transparent" width="425" height="350"></embed></object></p>
<p>Now <a href="http://www.informationweek.com/security/showArticle.jhtml?articleID=201807006">Information Week reports</a>:</p>
<blockquote><p><span id="articleBody"> An attorney launching a class-action lawsuit against TD Ameritrade Holding alleges the online brokerage knew a hacker had access to a customer database as far back as a year ago.</span></p></blockquote>
<p>Information Week  indicates the company has responded:</p>
<blockquote><p> Kim Hillyer, a spokeswoman for Ameritrade, said in an interview that all of the company&#8217;s 6.3 million accounts that were opened before July 18 of this year were breached. She would not say when the company first learned that there had been a breach, only offering that &#8220;they had been investigating client reports of spam <a href="http://www.informationweek.com/security/showArticle.jhtml?articleID=201807006#" itxtdid="3802270" target="_blank" style="border-bottom: medium none; font-weight: bold; text-decoration: none; padding-bottom: 0px; color: darkblue; background-color: transparent; cursor: pointer" classname="iAs" class="iAs"><nobr></nobr></a> for some time.&#8221;</p>
<p>She said in the last few weeks they discovered that malicious code had been embedded in the system. She would not say what part of the system was infected or what kind of code it was. &#8220;We have been working with forensics,&#8221; she said. &#8220;They said they&#8217;ve never seen it before.&#8221;</p>
<p>Hillyer also said that while the investigation was ongoing, as new customers came on board, the company put their information in the compromised database. &#8220;We didn&#8217;t know what the cause of the leak was,&#8221; she added. &#8220;Anyone who opened an account after July 18, though, was not affected by this.&#8221;</p></blockquote>
<p><a href="http://www.kqzyfj.com/click-2567372-10437588" target="_top"><br />
<img src="http://www.tqlkg.com/image-2567372-10437588" width="180" height="150" alt="LifeLock Identity Theft Prevention - Save 10% " border="0"/></a><br /></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.privacymaven.com%2Ftd-ameritrade-may-have-known-of-data-breach-a-year-ago.html';
  addthis_title  = 'TD+Ameritrade+May+Have+Known+of+Data+Breach+a+Year+Ago';
  addthis_pub    = '';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.privacymaven.com/td-ameritrade-may-have-known-of-data-breach-a-year-ago.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
