Latest Comments
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"I have been the recipient of Agent.JEN.Trojan through an email suggesting a UPS parcel (including..."
by Vincent Laing | Nov 13, 2008 4:01 PM

HBOS: Lost data disk was not encrypted

  • Email a Friend
  • Print Page
By Fiona Raisbeck
Jun 12, 2007 10:17 AM
Tags: HBOS: | Lost | data | disk | was | not | encrypted
The CD contained the personal information, including names, addresses, dates of birth and mortgage account numbers, of more than 62,000 mortgage customers of the Edinburgh-based arm of the HBOS banking group.

The disk was lost after it was posted to a credit reference agency, which reported the information missing when it failed to receive its monthly batch of data.

“The disk would usually be encrypted,” said a spokesperson for HBOS. “Unfortunately, due to human error on this occasion the usual policy was not followed. We apologise to our customers for this.”

As a result of this breach the bank is writing to all the customers involved warning them of the risks of identity theft, and offering them free credit reference checks.

“This case highlights the need for encryption of sensitive information by companies, especially where customer data is involved,” said Calum Macleod, European director for Cyber-Ark.

In March, thousands of Halifax - another subsidiary of HBOS – customers demanded answers after a computer printout of their personal details was snatched from an employee’s car.

The bank sent written apologies to the 13,000 people affected and reiterated that lessons had been learnt and claimed that the company was “reviewing procedures as a matter of urgency.”

Macleod added: “Considering the bank's sister organisation also had a similar incident you'd think they would have reviewed their data security policies by now.

It still comes as a surprise that so many organisations are still using such archaic methods [to protect sensitive data]. The technology required to eliminate these threats costs a fraction of the money that HBOS will now have to spend to recover from this single incident."

A Royal Mail spokesman said: "The Royal Mail advises customers that when sending important information to use a special delivery service." The postal service loses 0.07 per cent of the items posted each year.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Breaches & Exposures Whitepapers