Itrcbreachreport2013.Pdf
Total Page:16
File Type:pdf, Size:1020Kb
Report Date: Identity Theft Resource Center 2/27/2015 2013 Breach List: Breaches: 614 Exposed: 62,001,589 Page 1 of 122 How is this report produced? What are the rules? See last page of report for details. ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20131231-05 Lakes Liquor MN Electronic Business Yes - Unknown # 0 **ITRC does not consider a password adequate protectionA security for breachedbreach that data. compromised hundreds of debit and credit cards in Becker County has been traced to Lakes Liquor in Detroit Lakes. Customers who used a card at the store between Oct. 27 and Nov. 25 may be affected. Information involved customer names, credit or debit card numbers, the card's expiration date and security code. People should check their credit report, review account statements and contact the bank that issued the card to check for suspicious or unusual activity. Attribution 1 Publication: kfgo.com / privacyrights.org Author: Date Published: Article Title: Security breach traced to Detroit Lakes liquor store Article URL: http://kfgo.com/news/articles/2013/dec/24/security-breach-traced-to-detroit-lakes-liquor-store/ ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20131231-04 Orient-Express Hotels NY Electronic Business Yes - Unknown # 0 **ITRC does not consider a password adequate protectionThe Orient-Express for breached Hotelsdata. Ltd. and its subsidiaries have notified an unspecified number of customers of a breach involving their credit card information. Attribution 1 Publication: databreaches.net / NH AG's office Author: Date Published: Article Title: Orient-Express Hotels Article URL: http://www.databreaches.net/orient-express-hotels-notifies-guests-after-data-security-breach/ ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20131231-03 RegistratioNATION IL Electronic Business Yes - Unknown # 0 **ITRC does not consider a password adequate protectionOn November for breached 22, 2013, data. RegistratioNATION discovered that a limited number of customer records may have been exposed due to a November 4, 2013 cyber-attack on our computer systems. As a result, the unauthorized user may have obtained your first and last name, date of birth, credit or debit card number, credit card verification code and billing address associated with your account. RegistratioNATION does not collect your social security number. Attribution 1 Publication: NH AG's office - databreaches.net Author: Date Published: Article Title: RegistratioNATION Article URL: http://doj.nh.gov/consumer/security-breaches/documents/registrationation-20131223.pdf ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20131231-02 Actelis Networks CA Electronic Business Yes - Unknown # 0 **ITRC does not consider a password adequate protectionWe write for to breached inform you data. about the recent theft of two locked safes that contained password-protected files that occurred on approximately December 7 or 8,2013. The stolen files may have contained some of your personal information, including your name, contact information, and social security number which Actelis maintains in connection with employment and related business purposes. Attribution 1 Publication: NH AG's office - databreaches.net Author: Date Published: Article Title: Actelis Networks Article URL: http://doj.nh.gov/consumer/security-breaches/documents/actelis-networks-20131213.pdf ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20131231-01 T-Mobile WA Electronic Business Yes - Unknown # 0 **ITRC does not consider a password adequate protectionWe are for writing breached to inform data. you of a recent incident of unauthorized access to a file stored on servers owned and managed by a T-Mobile supplier. This file contained personal information, including name, address, Social Security number and/or Driver’s License number. Attribution 1 Publication: CA AG's office / MD AG's office Author: Date Published: Article Title: T-Mobile Article URL: https://oag.ca.gov/system/files/Customer%20Notice_Final_Generic%20version_0.pdf? Copyright 2014 Identity Theft Resource Center Report Date: Identity Theft Resource Center 2/27/2015 2013 Breach List: Breaches: 614 Exposed: 62,001,589 Page 2 of 122 How is this report produced? What are the rules? See last page of report for details. ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20131230-06 Barnabas Health Medical NJ Electronic Medical/Healthcare Yes - Published # 1,100 Group **ITRC does not consider a password adequate protectionAn unencrypted for breached laptop data. was stolen on September 24, 2013 from the Barnabas Health Medical Group‘s Pediatric Specialty Center, which was then located in Livingston, NJ. The theft was detected on that same day, and internal security and the police were promptly notified, but the laptop has not yet been recovered. Letters were sent to all affected patients, using the addresses we have on file for those patients. Attribution 1 Publication: phiprivacy.net Author: Date Published: Article Title: Barnabas Health Medical Group Article URL: http://www.phiprivacy.net/nj-barnabas-health-notified-patients-after-laptop-with-with-pediatric-patients-pulmonary-testi ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20131230-05 Department of Health Care CO Electronic Government/Military Yes - Published # 1,918 Policy and Financing **ITRC does not consider a password adequate protectionThe Department for breached of Health data. Care Policy and Financing announced today that client information was sent from a work to a personal email address by a temporary employee of its contractor, the Colorado Community Health Alliance (CCHA). The list may have been sent for the employee’s personal use in a separate business. The information did Attribution 1 Publication: phiprivacy.net Author: Date Published: Article Title: Department of Health Care Policy and Financing (Colorado Medicaid) Article URL: http://www.phiprivacy.net/colorado-notifies-1918-medicaid-clients-of-hipaa-breach-by-contractors-employee/ ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20131230-04 Cruises Inc. FL Electronic Business Yes - Unknown # 0 **ITRC does not consider a password adequate protectionOur client, for breachedCruises Inc., data. recognizes the impor1ance of the privacy and confidentiality of the personal information provided by its current and prospective customers. Regrettably, on October 23, 2013, Cruises Inc. discovered that an unauthorized person gained access to the booking system using the log-in credentials of an authorized user. Although credit card information is encrypted when it is stored in the booking system, the unauthorized person used a decryption feature of the system to view the credit card number and expiration date for a limited number of individuals Attribution 1 Publication: MD AG's office Author: Date Published: Article Title: Cruises Inc. Article URL: http://www.oag.state.md.us/idtheft/Breach%20Notices/itu-235007.pdf ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20131230-03 City of Sumner WA Electronic Government/Military Yes - Published # 3,600 **ITRC does not consider a password adequate protectionSome 3,600for breached people willdata. soon get an unwelcome letter from the city of Sumner alerting them to a security breach. A temporary municipal court clerk is accused of transferring the residents' information to her personal computer. She said she was doing it so she could learn more about the Sumner Municipal Court way of doing things. Attribution 1 Publication: KIROTV.com Author: Deborah Horne Date Published: Article Title: Sumner residents getting letters because of data breach Article URL: http://www.kirotv.com/news/news/sumner-residents-getting-letters-because-data-brea/ncXyG/ ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20131230-02 South Carolina Health SC Electronic Medical/Healthcare Yes - Published # 3,432 Insurance Pool **ITRC does not consider a password adequate protectionA laptop for stolen breached from data.an auditor's car contained the personal information of more than 3,400 members of the South Carolina Health Insurance Pool. CHANGED FROM GOVERNMENT TO MEDICAL PER HHS 2/2014 An attorney hired by the pool told The Associated Press on Monday the laptop contained names and Social Security numbers of 3,432 members who were part of the high-risk pool in 2011 and 2012. Attribution 1 Publication: WISTV.com / hhs.gov Author: Date Published: Article Title: South Carolina Health Insurance Pool Article URL: http://www.wistv.com/story/24323194/laptop-with-data-of-schip-customers-stolen Copyright 2014 Identity Theft Resource Center Report Date: Identity Theft Resource Center 2/27/2015 2013 Breach List: Breaches: 614 Exposed: 62,001,589 Page 3 of 122 How is this report produced? What are the rules? See last page of report for details. ITRC Breach ID Company or Agency State Est. Date Breach Type Breach Category Records Exposed? # Records Rptd ITRC20131230-01 StakerLaw Tax and Estate TX Electronic