Data brokers didn't notify consumers of past breaches
LexisNexis, ChoicePoint execs grilled by Senate panel
IDG News Service - WASHINGTON -- Two large data brokers that recently reported data breaches potentially affecting hundreds of thousands of U.S. residents have been compromised in the past and have not notified victims, executives from the two companies told a U.S. Senate committee today.
Executives from ChoicePoint Inc. and LexisNexis, under questioning from Sen. Dianne Feinstein (D-Calif.), told the Senate Judiciary Committee that they did not report some data breaches to potential victims before a California law requiring notification went into effect in 2003.
A LexisNexis executive also told the committee that law enforcement agencies have reported 10 incidents of potential identity theft, in which new e-mail or credit-card accounts were opened, related to a recent LexisNexis breach where about 310,000 U.S. residents' records may have been compromised.
Feinstein and committee Chairman Arlen Specter (R-Pa.) questioned the two companies' efforts to notify victims during recently announced breaches of their multibillion-record databases. The companies' databases contain personal information such as driver's license numbers and Social Security numbers.
Specter demanded that LexisNexis provide a detailed explanation in writing of why the company took until Tuesday to announce that 280,000 more U.S. residents may be victims of a recent breach, up from the 32,000 people the company identified in early March (See story). LexisNexis began investigating the breach at its Seisint division, which occurred when thieves gained access to legitimate database passwords in February, said Kurt Sanford, president and CEO of U.S. corporate and federal markets for LexisNexis.
"Didn't you know about the breach in February?" Specter asked.
"I didn't know what I had until I did an investigation, Senator," Sanford answered.
Sanford didn't give an exact number, but he did say the company had some breaches it didn't report to potential victims before the California notification law went into effect. LexisNexis has uncovered 59 breaches, some dating back to early 2003, through the investigation started in February, Sanford said.
Victims of the LexisNexis breaches will get free credit report and credit monitoring services, free credit counseling services and free identity theft insurance, Sanford said. "We will begin notifying those individuals immediately," he said.
In at least one case in 2001, ChoicePoint did not report a breach to victims because it was not told of the focus of a law enforcement investigation that uncovered the compromise, said Douglas Curling, president and chief operating officer of ChoicePoint.
"If it weren't for the California law, we would have no way of knowing the breaches that have occurred," Feinstein responded.
ChoicePoint has found 45 to 50 data breaches, mostly



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All Privacy White Papers
- A Road Map for Best Practice Social Media Acceptable Use Policy
- Organizations around the world are racing to leverage the power of social media for business. Sites like Facebook are used for marketing, human...
- Data Protection and Disaster Recovery with iSCSI and VMware
- Get this on demand webcast now
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and... All Privacy Webcasts