Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

Data brokers didn't notify consumers of past breaches

LexisNexis, ChoicePoint execs grilled by Senate panel

April 13, 2005 12:00 PM ET

IDG News Service - WASHINGTON -- Two large data brokers that recently reported data breaches potentially affecting hundreds of thousands of U.S. residents have been compromised in the past and have not notified victims, executives from the two companies told a U.S. Senate committee today.
Executives from ChoicePoint Inc. and LexisNexis, under questioning from Sen. Dianne Feinstein (D-Calif.), told the Senate Judiciary Committee that they did not report some data breaches to potential victims before a California law requiring notification went into effect in 2003.
A LexisNexis executive also told the committee that law enforcement agencies have reported 10 incidents of potential identity theft, in which new e-mail or credit-card accounts were opened, related to a recent LexisNexis breach where about 310,000 U.S. residents' records may have been compromised.
Feinstein and committee Chairman Arlen Specter (R-Pa.) questioned the two companies' efforts to notify victims during recently announced breaches of their multibillion-record databases. The companies' databases contain personal information such as driver's license numbers and Social Security numbers.
Specter demanded that LexisNexis provide a detailed explanation in writing of why the company took until Tuesday to announce that 280,000 more U.S. residents may be victims of a recent breach, up from the 32,000 people the company identified in early March (See story). LexisNexis began investigating the breach at its Seisint division, which occurred when thieves gained access to legitimate database passwords in February, said Kurt Sanford, president and CEO of U.S. corporate and federal markets for LexisNexis.
"Didn't you know about the breach in February?" Specter asked.
"I didn't know what I had until I did an investigation, Senator," Sanford answered.
Sanford didn't give an exact number, but he did say the company had some breaches it didn't report to potential victims before the California notification law went into effect. LexisNexis has uncovered 59 breaches, some dating back to early 2003, through the investigation started in February, Sanford said.
Victims of the LexisNexis breaches will get free credit report and credit monitoring services, free credit counseling services and free identity theft insurance, Sanford said. "We will begin notifying those individuals immediately," he said.
In at least one case in 2001, ChoicePoint did not report a breach to victims because it was not told of the focus of a law enforcement investigation that uncovered the compromise, said Douglas Curling, president and chief operating officer of ChoicePoint.
"If it weren't for the California law, we would have no way of knowing the breaches that have occurred," Feinstein responded.
ChoicePoint has found 45 to 50 data breaches, mostly


Reprinted with permission from

IDG.net
Story copyright 2009 International Data Group. All rights reserved.

Additional Resources

POLL RESULTS
Accelerate your knowledge of the IT world you inhabit by viewing the results of a series of polls taken by your IT peers. These polls of 100+ IT professionals each are available for full viewing. They cover key topics such as virtualization, processor performance, green IT, cloud computing and many others. Be a part of the buzz.
WHITE PAPER
Technology is complex. Keeping it running productively shouldn't be. To that end, you want to minimize the number of solutions needed in-house to simplify operations, maintenance, and support. Kodak offers a best-practices model. One company provides support for both scanner and software, for fast problem resolution without vendor finger-pointing. Download now!
WHITE PAPER
Utilizing demand intelligence improves the precision of pricing, product assortments, channel/store placement, and promotion, which are all essential for sustainable revenue management performance. Learn more, download this free whitepaper today.

White Papers & Webcasts

Accelerate SSL Encrypted Applications
The amount of SSL traffic is growing in the enterprise. Because it is encrypted, it cannot be properly controlled and accelerated. Blue Coat...  

Data Protection and Disaster Recovery with iSCSI and VMware
Data protection and disaster recovery are top of mind for any IT manager, and the challenges of complexity and cost remain as obstacles....

ESG Lab Field Audit
Many companies have successfully implemented Riverbed WAN optimization solutions within their Cisco networks. This ESG Lab Field Audit document explores the success that...  

Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....

Shape Your Apps Strategy to Reflect New SaaS Licensing and Pricing Trends
Why are smart companies choosing software-as-a-service? Find out in the complimentary Forrester Research report...  

The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....

Natural User Interface for Enterprise Applications
Learn how a revolutionary user interface can make a complex enterprise application so intuitive even casual users can jump right in....  

SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....

A Truly Global HCM System
Learn about a system built with advanced object-oriented technology that support multi-national requirements and costs less to implement, maintain and upgrade....  

Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...