ITRC Article Database
Total Page:16
File Type:pdf, Size:1020Kb
Identity Theft Resource Center Report Date: 12/31/2007 Page 1 of 136 2007 Breach List: Breaches:446 Exposed: 127,717,24 How is this report produced? What are the rules? See last page of report for details. Records Exposed # of ITRC Breach ID Company or Agency Location Est. Date Breach Type Breach Category Exposed? Records Rptd ITRC20071231-02 Minnesota Department of MN 12/6/2007Electronic Government/Military Yes - 219 Commerce (Password) **ITRC does not consider a password adequate protection for breached data. A laptop with the names, SSNs and state license numbers for 257 applicents/licensees in the licensing system was stolen. The laptop was used to support and test the real estate, abstractors, appraisers and debt collection licensing system and data base used by several states including Minnesota. At the time of the theft, Promissor believes a limited amount of applicant/licensee information was stored on the hard drive of the computer, which was password protected, but not encrypted. Attribution 1 Publication: Pioneer PressAuthor: Bill Salisbury Date Published: 12/28/2007 Article Title: Stolen Laptop had Minnesotans' personal info, state agency says Article URL: http://www.twincities.com/allheadlines/ci_7830298?nclick_check=1 Attribution 2 Publication: press releaseAuthor: Minnesota Departmen Date Published: 12/28/2007 Article Title: Laptop Stolen From Department of Commerce Vendor Contains Personal Information for 219 Minnesota Licensed Professi Article URL: http://www.state.mn.us/portal/mn/jsp/content.do?id=-536882793&subchannel=null&sc2=null&sc3=null&contentid=5 Records Exposed # of ITRC Breach ID Company or Agency Location Est. Date Breach Type Breach Category Exposed? Records Rptd ITRC20071231-01 US Air Force US 11/19/2007Electronic Government/Military Yes - 10,501 Published # On November 18, a laptop belonging to an Air Force band member at Bolling Air Force Base in DC turned up missing. The information included SSNs, birth dates, and telephone numbers of active and retired Air Force members. The Air Force tells WSFA 12 News it was intended to be used for an Air Force Band Historical Documentation. Attribution 1 Publication: WSFA 12 TVAuthor: staff Date Published: 12/28/2007 Article Title: WSFA 12 News Update on Missing Air Force Computer Article URL: http://www.wsfa.com/Global/story.asp?S=7554385&nav=menu33_3 Attribution 2 Publication: WSFA TVAuthor: Sally Pitts Date Published: 12/28/2007 Article Title: Montgomery Man's Personal Information on Missing Military Computer Article URL: www.wsfa.com/Global/story.asp?S=7550098&nav=0RdE Records Exposed # of ITRC Breach ID Company or Agency Location Est. Date Breach Type Breach Category Exposed? Records Rptd ITRC20071228-01 Davidson County Election TN 12/24/2007Electronic Government/Military Yes - 337,000 Commission Published # Computers weres stolen by thieves that broke into the Metro Election Commioner's office. While information on voters was taken there is no risk of harm since only the last 4 numbers of the SSN were on the file. UPDATE: 12/29: Further investigation has discovered that the FULL SSN was in the database. Attribution 1 Publication: TenneseanAuthor: Jennifer Brooks Date Published: 12/29/2007 Article Title: Computer heist puts voter IDs in danger Article URL: http://tennessean.com/apps/pbcs.dll/article?AID=/20071229/NEWS0202/712290372/1009/NEWS Attribution 2 Publication: WSMV NewsAuthor: Chris Tatum Date Published: 12/27/2007 Article Title: Laptops Containing Voter Information Stolen Article URL: http://www.wsmv.com/news/14934234/detail.html Identity Theft Resource Center Report Date: 12/31/2007 Page 2 of 136 2007 Breach List: Breaches:446 Exposed: 127,717,24 How is this report produced? What are the rules? See last page of report for details. Records Exposed # of ITRC Breach ID Company or Agency Location Est. Date Breach Type Breach Category Exposed? Records Rptd ITRC20071224-04 MoneyGram MN 12/1/2006Electronic Business Yes - 79,000 Published # Per a press release, 80,000 MoneyGram customers have been notified that a hacker may have stolen their names, loan account#, bank routing numbers and bank account numbers. According to one expert, it involved customers who made payments to a single biller. Attribution 1 Publication: Bloomberg NewsAuthor: Yalman Onaran and E Date Published: 1/13/2007 Article Title: Breach affects 79,000 MoneyGram accounts Article URL: http://seclists.org/isn/2007/Jan/0071.html Attribution 2 Publication: breach listAuthor: WI Office of Privacy P Date Published: 1/12/2007 Article Title: MoneyGram breach Article URL: http://privacy.wi.gov/databreaches/2007/jan07.jsp Attribution 3 Publication: ReutersAuthor: staff Date Published: 1/12/2007 Article Title: MoneyGram security breach affects 79,000 customers Article URL: http://www.reuters.com/article/companyNewsAndPR/idUSWEN214220070112 Records Exposed # of ITRC Breach ID Company or Agency Location Est. Date Breach Type Breach Category Exposed? Records Rptd ITRC20071224-03 Bellin Health Family Medical WI 3/15/2007Paper Data Medical/Healthcare Yes - 650 Center Published # According to a listing in the WI Office of Privacy Protection, the Bellin Health Family Medical Center in Green Bay WI had patient names, SSNs, dates of birth and limited medical information stolen after a federal law enforcement action at a local home found documents from the Center. Attribution 1 Publication: breach listAuthor: WI Office of Privacy P Date Published: 5/3/2007 Article Title: Bellin Health Family Medical Center breach Article URL: http://privacy.wi.gov/databreaches/2007/may07.jsp Records Exposed # of ITRC Breach ID Company or Agency Location Est. Date Breach Type Breach Category Exposed? Records Rptd ITRC20071224-02 WI Assoc. of Lakes, Inc WI 6/1/2007Electronic Business Yes - 180 Published # The names, dates of birth, and credit card numbers may be affected due to the hacking of the WI Assoc. of Lakes online store. The online store was deactivated on June 12 and all individuals contacted. Attribution 1 Publication: breach listAuthor: WI Office of Privacy P Date Published: 6/15/2007 Article Title: Wisconsin Association of Lakes breach Article URL: http://privacy.wi.gov/databreaches/2007/june07.jsp Identity Theft Resource Center Report Date: 12/31/2007 Page 3 of 136 2007 Breach List: Breaches:446 Exposed: 127,717,24 How is this report produced? What are the rules? See last page of report for details. Records Exposed # of ITRC Breach ID Company or Agency Location Est. Date Breach Type Breach Category Exposed? Records Rptd ITRC20071224-01 Ventura County Superior CA 11/1/2007Paper Data Government/Military Yes - 4 Court Published # Despite a policy to shred, documents containing 4 people's SSNs and bank account numbers were found in a trash bin outside of the Ventura County Superior Court in November. Attribution 1 Publication: Ventura County StarAuthor: Tony Biasotti Date Published: 12/22/2007 Article Title: Social Security numbers, bank data vulnerable Article URL: http://www.venturacountystar.com/news/2007/dec/22/sensitive-papers-unguarded-near-superior-court/ Records Exposed # of ITRC Breach ID Company or Agency Location Est. Date Breach Type Breach Category Exposed? Records Rptd ITRC20071221-12 UnitedHealthcare MO Electronic Business Yes - 17,000 Published # A former UnitedHealthcare employee is amont the suspected particpants in stealing at least 127 member's information and as many as 17,000. The information includes names, dates of birth and SSNs. UnitedHealthcare is working with a Federal Task Force on this case. The suspect worked for the company for 2 1/2 years. Attribution 1 Publication: UnitedHealthcare notice to NH AGAuthor: Douglas Niska Date Published: 6/25/2007 Article Title: UnitedHealthcare breach Article URL: http://doj.nh.gov/consumer/pdf/united_health.pdf Records Exposed # of ITRC Breach ID Company or Agency Location Est. Date Breach Type Breach Category Exposed? Records Rptd ITRC20071221-11 Textron RI Electronic Business Yes - 0 (Password) **ITRC does not consider a password adequate protection for breached data. In June Textron had a laptop stolen that included current and former employee names, SSNs and account numbers. 475 NH residents were affected. Attribution 1 Publication: Textron notice to NH AGAuthor: Susan Hamlyn Date Published: 7/31/2007 Article Title: Textron breach Article URL: http://doj.nh.gov/consumer/pdf/textron.pdf Records Exposed # of ITRC Breach ID Company or Agency Location Est. Date Breach Type Breach Category Exposed? Records Rptd ITRC20071221-10 Sungard Higher Education PA 2/12/2007Electronic Business Yes - 0 Unknown # A thief stole a laptop from a parked SunGard employee's vehicle. Names, SSNs, bank transfer ABA numbers and account number and/or credit card information may have been on the laptop. Attribution 1 Publication: notice to NH AGAuthor: Randi Serota Date Published: 3/19/2007 Article Title: SunGard Higher Education breach Article URL: http://doj.nh.gov/consumer/pdf/sungard.pdf Identity Theft Resource Center Report Date: 12/31/2007 Page 4 of 136 2007 Breach List: Breaches:446 Exposed: 127,717,24 How is this report produced? What are the rules? See last page of report for details. Records Exposed # of ITRC Breach ID Company or Agency Location Est. Date Breach Type Breach Category Exposed? Records Rptd ITRC20071221-09 Student Loan Corporation CT 8/1/2007Electronic Banking/Credit/Financial Yes - 519 Published # A portable computer was stolen from an office of a third party vendor. It may have contained names, SSNs and email addresses. Attribution 1 Publication: Student Loan CorpAuthor: James Nelson, Busin Date Published: 8/9/2007 Article Title: Student Loan Corporation breach Article URL: http://doj.nh.gov/consumer/pdf/student_loan2.pdf Records Exposed # of ITRC Breach ID Company or Agency Location Est. Date Breach Type Breach Category Exposed? Records Rptd ITRC20071221-08 Public Storage, Glendale CA 12/11/2006Electronic Business Yes - 0 Unknown # Public Storage in Glendale, CA notified the NH AG that someone gained access to electronic company personnel files at their corporate offices. These included files for all active employees including SSNs, dates of birth and payrolll information.