Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

More personal data said to be on stolen Ohio government backup tape

The loss is expected to cost the state nearly $3M

September 11, 2007 12:00 PM ET

Computerworld - A computer forensics expert has uncovered an additional 106,821 pieces of personal data on a copy of a stolen backup tape removed from the car of an intern responsible for carrying data used by the Ohio state government's computer systems. The finding, released in two reports on Monday by Interhack Corp., arrives three months after the incident occurred.

In its report, Columbus, Ohio-based Interhack said the missing backup tape featured newly discovered names and Social Security numbers of 47,245 individuals; the names and Social Security numbers of 19,388 former state employees; and banking information on less than 100 businesses, according to Ron Sylvester, a spokesman for the Ohio Department of Administrative Services.

Additionally, the names and federal employee identification numbers of 40,088 businesses were unearthed by Interhack. Information from that file was being used by the state's Ohio Administrative Knowledge System (OAKS) to help populate and test E-Controlling Board, a state Controlling Board business application.

Following Interhack's analysis, Sylvester confirmed that in total more than 1.3 million pieces of personal data were stored on the stolen backup tape. The groups affected include state taxpayers, Medicaid providers, payroll vendors, dependents, students and state government employees.

The incident is expected to cost the state almost $3 million. Of that total, $2.3 million covers projected and existing enrollment in Debix Inc. credit protection services. Debix enrollment paid for by the state for affected individuals will remain open until Oct. 31. Debix protection will not be extended toward any businesses with information on the lost backup tape.

At the time of its theft, the missing tape was being used to carry information from the government's office tower to an off-site location, where roughly 100 state workers and 100 Accenture employees are responsible for testing, configuring code and customizing PeopleSoft applications. That effort is part of Ohio's massive $158 million OAKS ERP project.

"The particular drive that this tape was used to back up... was the sort of the testbed drive, so a lot of data was real and historical data being used to test different parts of the OAKS system -- everything from payroll functionality to accounting functionality," said Sylvester. "That's why there were a lot of these files on here, because they were testing things like cutting purchase orders, paying mileage checks -- all the business processes that the current legacy systems use -- and making sure the way OAKS was being configured would work."

Since it was a temporary site, a network administrator from the state's previous administration had decided as part of his business continuity plan that he would take backup tapes home every night. However, Sylvester said over time that practice had "devolved" to include interns taking the tapes home.



Jump to comments

INterhack

Additional Resources

EFD vs. HDD - What You Need to Know
WHITE PAPER
Enterprise flash drives provide a new Tier 0 storage layer capable of delivering high I/O performance at a very low latency. Proper use of EFDs in an Oracle environment can deliver increased performance compared to fibre channel drives. Read the recommendations for identification of the best DB components for EFDs.
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009
WHITE PAPER
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.
Eight Criteria for Server Load Balancing
WHITE PAPER
Server load balancers are a simple yet highly effective means to scale an application environment while ensuring its availability. Today's solutions should also address application performance and security. Read about the top eight criteria you should consider when choosing a server load balancer and how Citrix NetScaler meets those requirements.

What People Are Saying

White Papers & Webcasts

Death to PST Files
Download Now  

Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".

eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...


IT Jobs