J.P. Morgan Chase probing data breach shown in YouTube video
The video appears to show client documents in garbage bags
Computerworld - Financial services firm J.P. Morgan Chase is investigating claims by a Washington, D.C.-based workers union that it dumped documents containing personal financial data belonging to its customers in garbage bags outside five branch offices in New York.
Separately, it is also sending out letters to tens of thousands of Chicago-area customers and some employees about the potential compromise of their account information after a tape containing the data was reported missing.
The Service Employees International Union, an organization claiming more than 1.8 million members countrywide, has posted a video on YouTube that supposedly shows documents containing account data -- including full customer names, addresses and Social Security numbers -- being discovered in trash bags outside the bank branches in and around New York City.
Among the documents the video purports to show being recovered from the garbage bags are a loan application with the borrower's name, address and Social Security number, a checking account profile with similar details, a partially ripped account summary with personal data and a business credit application. The video ends with a message urging viewers to call Tom Kelly, the bank's head of media relations for Retail Financial Services and the U.S. Region.
JP Morgan and the SEIU are currently locked in a labor dispute involving the hiring of security guards.
Kelly said that Chase is investigating the claims made by the SEIU in the YouTube video. According to Kelly, the standard procedure for disposing of financial documents at Chase branch locations is to put them into a large padlocked bin with an opening on top for inserting the documents. The papers are then later recovered from the bins and shredded. He added that the bins are not placed outside the facility.
"We don't know what happened here; we are trying to find out," he said. "We had a conference call with all of our branch managers and reiterated what our policies and procedures are" for document disposal.
The bank has also contacted the SEIU's attorney and asked the group to share the customer information it claims to have recovered from the branch locations, Kelly said. "If those customers are at risk, we want to contact them," he said, adding that so far the bank has not heard back from the SEIU. "It is not clear that customer privacy was their first priority in this."
A spokeswoman from the SEIU did not immediately respond to a request for comment.
Meanwhile, in a separate incident, the bank two weeks ago started alerting some 47,000 customers and employees in the Chicago area about the potential compromise of their personal data after a disk containing the data was reported missing late last year.
The tape contained data from J.P. Morgan's private-client services business, which provides financial services to clients with a net worth in excess of $1 million. According to Kelly, the tape was delivered to a secure off-site facility for storage but went missing after that. There is no evidence so far that the data has been misused, he said.
JP Morgan is offering a year's worth of credit monitoring services to affected clients. He also said that the bank took so long to inform affected individuals of the potential compromise because it needed to reconstruct the information contained on the tape.
Read more about Security in Computerworld's Security Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts