Two more organizations report data breaches
Texas Guaranteed, Sacred Heart University disclose separate incidents involving personal data
Computerworld - Advocates for strong data privacy laws are getting plenty of ammunition to support their cause these days.
In yet another large data breach, Texas Guaranteed (TG) a Round Rock, Texas-based nonprofit organization that administers student loans today announced that an outside contractor had lost an unspecified piece of equipment containing the names and Social Security numbers of approximately 1.3 million borrowers.
The loss was reported to the company on Friday by Hummingbird Ltd. a Toronto-based company that had been hired by TG to develop a document management system for TG. Kristin Boyer, a spokeswoman for TG said borrower files had been provided to Hummingbird as part of the contract.
According to Boyer, TG followed recommended security practices and encrypted all the information prior to transmitting it to Hummingbird. The data was then unencrypted by a Hummingbird employee and stored on equipment that later appears to have been lost, Boyer said.
"We don’t have any indications at this point if there was malicious intent," behind the disappearance of the data, she said.
In a statement, Hummingbird said there was no reason to believe that the piece of equipment had been stolen to gain access to confidential data. The statement also said that the data had been protected through unspecified "security measures," which would make it difficult for unauthorized people to access the data.
"Given the technology that would be required to retrieve the data, Hummingbird believes that any misuse of the data is extremely unlikely," the company said. The statement added that the company filed a lost property report with the police after having "exhausted every possibility to recover the stolen equipment."
TG has set up a call center at (800) 530-0626 to provide information to affected customers. The company also plans to start sending letters to all of the affected individuals in the next few weeks Boyer said.
The TG incident is the second one involving large amounts of personal data since the disaster at the Department of Veterans Affairs last week.
Rootkit detected at Sacred Heart University
On May 24, Sacred Heart University in Fairfield, Conn, announced that one of its computers had been hacked, resulting in the potential compromise of personal data belonging to 135,000 alumni and prospective students.
The breach was discovered May 8 when the university’s IT staff noticed "an anomaly during routine daily maintenance of our computer system," said Funda Alp, a university spokeswoman. A rootkit installed on the system, apparently by an outside attacker, caused it to crash one of the services running on a server containing the information, Alp said.
"When the breach was discovered, [the server] was taken off-line immediately," Alp said. She added that preliminary investigations appear to show that the hacker had the expertise to access the information stored on the server although it is not clear if that happened. Apart from the names, addresses and Social Security numbers of 135,000 people, the compromised server also contained credit-card information on 103 individuals, she said.
There is no indication that the information has been misused, Alp said, adding that the university began notifying affected individuals soon after the breach was discovered.
Read more about Security in Computerworld's Security Topic Center.
- Securing Mobility, From Device to Network At one time, the process of managing and securing mobile devices and applications was fairly straightforward. Most organizations worried about one application (email)...
- Data Protection eGuide In this eGuide, CSO and sister publications IDG News Service, Computerworld, and CIO pull together news, trend, and how-to articles about the increasingly...
- Warning: Cloud Data at Risk Experts agree that relying on SaaS vendors to backup and restore your data is dangerous. Yet that's exactly what huge portions of the...
- The Opportunities and Challenges of the Cloud In this report F5 poses questions to IDC analysts, Sally Hudson and Phil Hochmuth, on behalf of F5's customers to better understand the...
- What should I look for in a Next Generation Firewall? SANS Provides Guidance With so many vendors claiming to have a Next Generation Firewall (NGFW), it can be difficult to tell what makes each one different....
- Responding to New SSL Cybersecurity Threat The featured Gartner research examines current strategies to address new SSL cybersecurity threats and vulnerabilities. All Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!