Latest Comments
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM
 
"it's great i tried it"
by divyacharan | Nov 20, 2008 12:24 AM
 
"I actually love the RoboForm software myself. I use it all of the time and it takes all of the ..."
by Omarra Byrd | Nov 18, 2008 8:19 AM

Sensitive documents found in bank garbage; posted on YouTube

  • Email a Friend
  • Print Page
Sensitive documents found in bank garbage; posted on YouTube
By Dan Kaplan
May 2, 2007 9:57 AM
Tags: Union | discovers | sensitive | documents | in | Chase | bank | garbage, | posts | findings | on | YouTube
The Service Employees International Union, said to be protesting low wages of Chase bank security guards, are recorded searching plastic trash bags and discovering a number of documents, including bank statements, loan applications and transaction reports, that contain sensitive data such as Social Security numbers.

The "dumpster divers" blurred out the confidential data on the YouTube clip, which has received more than 5,000 views since being posted on Monday.

"We're going through the trash here to make sure they properly dispose of their customer information," one of the protesters said on the video.

The incident emphasizes the need for financial institutions to not only invest in technology, but also to ensure employees are complying with policies, Avivah Litan, a Gartner analyst, told SCMagazine.com. She said Chase has led the pack in online banking security but appears to have made a major mistake here.

"That's amazing that in this day and age, they would allow these kinds of documents to go into the garbage," Litan said. "That's really a bad slip-up."

Tom Kelly, a Chase spokesman, told SCMagazine.com today the bank is waiting for the union to report which customers were identified in the documents, at which time the bank will send notices to the victims. He expected the number of affected individuals to be in the dozens, or hundreds at most; all will be offered a free year of credit monitoring.

Kelly said he has no reason to believe any of the data will be misused.

He said established protocols call for such documents to be locked in bins, then shredded.

All New York branch managers were told on Monday to revisit their security policies to ensure this does not happen again, he said.

Gartner reported in March that about 15 million Americans were victimised by identity theft fraud during a 12-month period ending in the middle of 2006. Litan said paper document theft, such as dumpster diving, is responsible for a majority of new account fraud and check forgery.

Companies must do a better job at information lifecycle management, ensuring data is protected from creation to destruction, Jared Pfost, vice product of product management for biometrics authentication provider BioPassword, told SCMagazine.com.

"Identity theft can come at any stage in that lifecycle, whether [the data] is in electronic or physical format," he said.

Kelly said he was upset the union posted its findings on the internet instead of first notifying Chase. A union spokesman could not be reached for comment today.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Breaches & Exposures Whitepapers