Archive for November, 2007

VA Medical Center Breach

Saturday, November 24th, 2007

Data Loss Source: Two personal computers and a laptop computer were allegedly stolen from an unsecured room at the Roudebush VA Medical Center.
Date of Loss: Nov. 15, 2007
Size of Loss: 12,000
Affected Individuals: Veterans
Geographic Focus: Indianapolis, IN
Data contained: Names, Social Security numbers and dates of service of approximately 12,000 veterans.
Additional Notes:Roudebush is sending letters to all of the 12,000 veterans and the VA pays for a year of credit monitoring.
Additional Information: Wish TV 8

Commerce Bancorp Data Breach

Monday, November 19th, 2007

Data Loss Source: A Commerce Bancorp Inc. employee gave out personal information on an unspecified number of its customers.
Date of Loss: Nov. 13, 2007
Size of Loss: Unknown
Affected Individuals: Bank customers
Geographic Focus: Philadelphia, PA
Data contained: The Bank discovered the breach through an internal investigation and sent letters to affected customers. The bank does not know if the information included account numbers and Social Security numbers.
Additional Information: TradingMarkets.com

Not Your Average Joe’s Chain Data Breach

Monday, November 12th, 2007

Data Loss Source: A Massachusetts chain of restaurants, called Not Your Average Joe’s, was targeted by an individual or individuals seeking to illegally obtain credit card data.
Date of Loss: Oct. 24, 2007
Size of Loss: Unknown
Affected Individuals: Restaurant customers
Geographic Focus: Massachusetts
Data contained: “The activity occurred largely between early August and late September; there has been no evidence of any fraudulent activity subsequent to September 29,” the company said. “Based on preliminary conversations with the credit card companies, it appears that this issue has impacted significantly fewer than one percent of the nearly 350,000 customers we served during that period. Investigations indicate that no member of the Not Your Average Joe’s staff was involved.”
Additional Information: Boston Business Journals

Salesforce Data Breach

Friday, November 9th, 2007

Data Loss Source: Customers on a leaked Salesforce.com contact list have been receiving more phishing e-mails, which result in viruses or key loggers.
Date of Loss: Nov. 7, 2007
Size of Loss: Unknown
Affected Individuals: Customers
Geographic Focus: Global
Data contained: Names, company names, e-mail addresses, telephone numbers of Salesforce.com customers, and related administrative data belonging to Salesforce.com.
Additional Notes:: The contact list was leaked, it turns out, by a Saleforce.com employee who fell for a phishing scam him or herself, and revealed his or her own password that then led to a customer contact list being copied, according to the company.
Additional Information:eWeek

College Students and Employees Exposed in Breach

Thursday, November 8th, 2007

Data Loss Source: Montana State University is informing students and employees that their Social Security numbers may have been exposed in one of three data security breaches.
Date of Loss: Nov. 7, 2007
Size of Loss: 271
Affected Individuals: Students and employees who lived in on-campus housing from 1998 to the spring of 2007.
Geographic Focus: Montana
Data contained: Social Security numbers
Additional Notes:: On Nov. 2, it was determined that a stolen data storage device contained the Social Security numbers of 216 students and employees. In a separate incident that also occurred on Nov. 2, an independent security analyst informed university data security staff that an Excel spreadsheet with the names and Social Security numbers of 42 people was posted on the MSU Web site. University data security staff then discovered another Excel spreadsheet with the Social Security numbers of 13 people affiliated with the Department of Computer Science on the university’s Web site. Both spreadsheets were immediately removed.
Additional Information: Billings Gazette