Commerce Bank breached -- don't tell
Some customers are displeased with the (nearly) silent treatment
Computerworld - Commerce Bank of Cherry Hill, N.J has notified an unspecified number of its 3 million customers of a recent data breach involving the potential compromise of their personal data.
In an e-mailed statement to a query regarding the incident, a Commerce Bank spokesman only confirmed that a "security matter" had taken place recently that impacted "only a small segment" of its three million customers.
Without referring to what happened, the statement said that immediate actions had been taken to address "this matter," including an extensive internal investigation by the bank's corporate security team as well as notification about the incident to federal and state law enforcement authorities.
The email alluded to a letter sent by the bank to the affected customers, but did not say what information on them might have been compromised in the incident.
"If customers did not receive a specific letter regarding this incident there is no need for them to be concerned," the statement said.
Local media reports suggested that the compromise resulted when a bank employee apparently handed over customer information such as Social Security numbers and account information to an external third party. There was no indication, however, whether that happened inadvertently or was the result of a malicious action on the part of the employee.
One blogger on LiveJournal who claimed to be a customer of the bank said that a Commerce Bank representative had told her about 3,000 people had been affected in the incident. According to the blogger, her first indication that her account had been compromised came when she tried using her ATM card last week to withdraw some money and her card was rejected. A message on the transaction record indicted that her card had been retained by the bank though the card was still in her possession.
She claimed that bank representatives told her the card had been closed but offered no explanation, and asked her instead to come to the bank to get a new card. It was only after she mentioned seeing media reports about a security incident at Commerce Bank a few days later that a bank representative finally told her that if she had been impacted she would receive a letter in the mail shortly. The blogger claimed she had heard nearly identical stories from several others.
Banks named Commerce have had a tough go of it in 2007, with an identically named regional bank targeted by hackers earlier in the year. According to reports earlier in the fall, the bank was able to deflect most of a hacking attempt on its database, but not before some customer information was divulged.
The Commerce Bank spokesman who confirmed the current breach did not respond immediately to a request for comment on the claims made by the blogger, and there has been no claim that the two attacks are related.
Read more about Security in Computerworld's Security Topic Center.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- SaaS and Cloud ERP Trends, Observations, and Performance 2011
- Find out why more organizations are considering SaaS as the deployment model for their ERP implementations than ever before, and learn about the...
- An interactive eGuide: Healthcare IT
- In this eGuide, Computerworld along with sister publications CIO, InfoWorld, and CSO, examine some of the most pressing issues facing healthcare IT today....
- What to Look For in Solutions For Mobile Device Management
- Managing an increasingly mobile workforce has become one of the most challenging - and important - responsibilities for IT departments. This paper examines...
- Bank Improves Crisis Management Communications with Help from BlackBerry Solution
- With a staff of more than 60,000 people dispersed across the United States, U.S. Bank needed a robust and intuitive program that would...
- How to Effectively Secure Electronic Healthcare Records
- In the ongoing effort to reach HIPPA Electronic Medical Record (EMR) compliance standards, one of the biggest concerns is security. Keeping patient data... All Privacy White Papers
- Close a Dangerous Vulnerability: Automated Methods for Managing Admin Rights
- In this exclusive webcast from Viewfinity, you'll hear how to leverage Group Policy Object settings to close this vulnerability by elevating privileges for...
- Data Protection and Disaster Recovery with iSCSI and VMware
- Get this on demand webcast now
- Smarter Development and Testing for IBM® System z®
- Date/Time: June 19, 2012 at 11:00 a.m. EDT
Join us for this webcast and hear from IBM Distinguished Engineer Rosalind Radcliffe and David... - BlackBerry PlayBook OS 2.0 Security Overview
- The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
- Apps that add business value
- BlackBerry® has all that you need to leverage mobile applications for BlackBerry® smartphones and BlackBerry® PlayBook™ tablets. You will see some simple applications... All Privacy Webcasts