Ohio gov't. contractor suspected in 'Joe the Plumber' privacy breach
Records were accessed after his name came up in presidential debate
Computerworld - The Ohio State Highway Patrol has identified a suspect in a criminal case involving illegal access to information in a state government database about Joseph Wurzelbacher, the plumber made famous by Sen. John McCain (R-Ariz.) during the Oct. 15 presidential debate.
Sgt. Tim Karwatske, a spokesman for the state highway patrol, today said that the investigation is focusing on a contractor working for the Ohio Department of Insurance in Columbus. A Hewlett-Packard computer belonging to the agency has been seized as evidence, Karwatske said.
He did not name the person because the investigation is still under way and no formal charges have been filed in the case, he said.
The criminal investigation came at the behest of Ohio State Attorney General Nancy Rogers' office after it was discovered that someone had surreptitiously used an old test account created by the attorney general's IT team to access Wurzelbacher's records.
This is not the first time that reports of illegal access to records of high-profile persons by insiders with privileged access have surfaced during this election. Earlier this year, U.S. Department of State officials disclosed that private contract employees working for the agency had repeatedly accessed passport records belonging to McCain, Sen. Barack Obama (D-Ill.) Sen. Hillary Clinton, (D-N.Y.) and others.
Jennifer Brindisi, a spokeswoman for the Ohio attorney general's office, today said that the test account used to access Wurzelbacher's data was created four years ago during the development of Ohio's Local Law Enforcement Information Sharing Network (OLLEISN). The test account was shared with several unidentified contractors when OLLEISN was being built, Brindisi said.
When the illegal use of the account was discovered, the matter was turned over the Highway Patrol, which launched a criminal investigation into the unauthorized access, Brindisi said. "No one from the Attorney General's Office was involved in the unauthorized inquiry into Joe Wurzelbacher's records," Brindisi said via e-mail. The attorney general's office has changed the security codes and taken other "appropriate measures" to tighten access to OLLEISN data, Brindisi said.
OLLESIN was created by the Ohio Association of Chiefs of Police as a tool to help local law enforcement agencies in the state share multi-jurisdictional information on suspects, wanted individuals, warrants, incident data and field interview notes, according to an official description of OLLESIN.
The data behind OLLESIN is part of the state attorney general's Ohio Law Enforcement Gateway (OHLEG) Web portal and can be accessed either via a Web interface or through the Computer Aided Dispatch and Records Management Systems used by law enforcement officers. Users need individual accounts issued directly from the Rogers' office to access the records and all access is logged.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- Streamline Compliance and Increase ROI
- Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into... All Privacy White Papers
- A Road Map for Best Practice Social Media Acceptable Use Policy
- Organizations around the world are racing to leverage the power of social media for business. Sites like Facebook are used for marketing, human...
- Data Protection and Disaster Recovery with iSCSI and VMware
- Get this on demand webcast now
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and... All Privacy Webcasts