A Real Dumpster Dive: Bank Tosses Personal Data, Checks
CSO - Data protection is not just an IT security issue. But security industry analyst Steve Hunt, who heads up Hunt Business Intelligence, believes too many people in IT security still have that false perception.
"There are so many physical security aspects to data protection it ought to never be considered merely an IT security issue," Hunt said.
Instead, noted Hunt, sensitive data is sitting on USB drives, in the garbage, in the discarded fax pile and plenty of other places, waiting to be found by criminals. (For lots of additional examples of how sensitive information is lost or taken, see 9 Dirty Tricks: Social Engineers' Favorite Pickup Lines.
Good old-fashioned dumpster diving. It might sound like a 90s tactic, but Hunt thought it would still work as a way to garner sensitive information.With that in mind, Hunt headed to the trash bin at what he describes as "a big bank in a big city." He was in and out of the dumpster in three minutes, according to his estimate. In that short amount of time he came up with the following items (Check out the video below to see Hunt's walkthrough of the results):
Scoring Big in a Dumpster Dive
Steve Hunt reveals how easy it is to find sensitive information during a dumpster dive.
This player will be used for any in-article video treatment. This is a single video player.
Wire transfer information
Hunt obtained the wire transfer information of many transactions. The documents he found included transfer information for transactions between US banks and banks in Jordan, Saudi Arabia, Dubai and Portugal. The documents included the account numbers and social security numbers of both the sender and the receiver, and their names.
Check copy
Hunt found a clear and easily-readable copy of a bank check with all of the important information: Bank account number and routing number and name of the account holder. The account holder's social security number and small business ID number were hand written in on the top right of the check. (See Anatomy of a Fraud for an in-depth look at the damaging results of a check fraud case.)
Bank account transaction history
The dive also turned up the bank account numbers, balances and banking activity for the fundraising account of "a certain prominent politician in the area," according to Hunt.
Personal financial statement
Hunt found the personal financial statement of an individual he described as "very wealthy." The documents list the person's name, home address, real estate owned and values of the properties, several of the individual's bank account numbers, social security number and date of birth. Hunt Googled the name and easily found a picture of the person.
An entire, intact PC
Hunt's experiment even yielded a whole laptop with a tag on the back that says "Property of [another financial institution]". While the computer had no power and Hunt was not able to power it up, "I know how to connect to a hard drive," he noted. (See How to Get Rid of Old Computers for a safe disposal process.)



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Forrester Total Economic Impact (TEI) Case Study - Oracle
- In this paper, Forrester Consulting examines the total economic impact and potential return on investment (ROI) realized by three Enterprise organizations as they...
- The Hidden Truth About Virtualizing Business-Critical Applications
- This IDG whitepaper highlights key findings based on the Quickpoll Survey conducted with more than 300 Enterprise and Commercial IT decision makers worldwide...
- Top 10 Myths About Virtualizing Business-Critical Applications
- Even though virtualization has brought positive change to enterprise IT over the last decade, some skepticism remains about how valuable virtualization can be...
- Enterprise Java Applications on VMware: Unix to Linux Migration Guide
- This guide focuses on key considerations for IT Architects who are in the process of migrating Java applications from UNIX to Linux as...
- Virtualizing Tier 1 Applications: A Critical Step on the Journey Toward the Private Cloud
- This IDC white paper explains how much of the Enterprise IT community is at a crossroads in extending their journey to the private... All Applications White Papers
- Live Webcast
Banish Poor Application Performance: Eliminate Business Disruptions, Increase End User Productivity - End User Experience, 30-Min Webinar
Wed. Feb. 22nd ~ 11 AM ET
Are you ready to gain the proactive ability to rapidly respond... - Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®...
- Discover the Benefits of Virtualization for Federal Applications
- Want to say goodbye to missed SLAs? VMware can help you virtualize mission-critical applications such as Oracle, MS Exchange and SharePoint to achieve...
- Reduce Application Lifecycle Management Costs with VMware ThinApp
- Traditional desktop application deployment and management is a time-consuming and costly endeavor for IT. From development to deployment, including help desk support, the... All Applications Webcasts