Original URL: http://www.theregister.co.uk/2007/09/28/gap_data_breach/
A laptop containing unencrypted personal information for 800,000 people who applied for jobs with clothing retailer Gap Inc. has been stolen.
The computer contained social security numbers and other sensitive information belonging to residents of the US and Puerto Rico who applied online or by phone for jobs from July 2006 to June 2007, the retailer said in this list (http://www.gapsecurityassistance.com/faq.htm) of frequently asked questions. Details for applicants living in Canada were also exposed, although they didn't include social insurance numbers.
The laptop was stolen from the offices of a third-party vendor the Gap hired to manage applicant data. The Gap didn't identify the vendor or explain why it failed to encrypt such a large number of applicants' personal information.
Gap joins scores of other organizations that have lost sensitive information entrusted to them. The US Department of Veterans Affairs, IBM and VeriSign have also been dogged by laptops or storage tapes that weren't encrypted and were later lost or stolen.
More recently, high-stakes data breaches have resulted from criminals who found ways to exploit weaknesses in corporate networks. Last week, TD Ameritrade said hackers infiltrated a database containing social security numbers, birth dates and account numbers on an undisclosed number of clients. And in August, cyber gumshoes discovered a Trojan that stole more than 1.3 million records from people who were looking for work through job recruiter Monster.com.
Few companies disclose details of their data-retention policies, such as whether computers containing sensitive information are encrypted. This is partly because the release of too much information can tip off criminals. But we can't help thinking the lack of disclosure also gives lawyers wriggle room in the event something goes wrong.
Indeed, Gap's FAQ didn't say whether customer records, applicant information and other sensitive details in its possession are encrypted, or whether it plans to enforce such a policy in the future. The Associated Press, however, quoted Glenn Murphy, the company's CEO and chairman saying the storing of applicant data without encrypting it ran contrary to Gap's agreement with the third-party vendor.
Gap is contacting applicants based in the US and Puerto Rico who had their social security numbers exposed. It is also arranging for them to receive one year of free credit monitoring. The company said it is unaware of any of the data being misused. ®
Privacy breach nuked in Canadian passport site (4 December 2007)
http://www.theregister.co.uk/2007/12/04/canadian_passport_site_breach/
Lost CD may put pension holders in peril (5 November 2007)
http://www.theregister.co.uk/2007/11/05/standard_life_lost_cd_security_flap/
Tax man praised for owning up to lost laptop (8 October 2007)
http://www.theregister.co.uk/2007/10/08/hmrc_lost_laptop/
Canadian privacy commissioner slams TJX data policy (27 September 2007)
http://www.theregister.co.uk/2007/09/27/tjx_data_leak_report/
California returns once more unto the breaches (18 September 2007)
http://www.theregister.co.uk/2007/09/18/california_security_breach_bill/
Europe claims UK botched one third of Data Protection Directive (18 September 2007)
http://www.theregister.co.uk/2007/09/18/ec_data_protection_act_objections/
Hackers infiltrate TD Ameritrade client database (15 September 2007)
http://www.theregister.co.uk/2007/09/15/ameritrade_database_burgled/
Monster Trojan monsters job seekers' records (21 August 2007)
http://www.theregister.co.uk/2007/08/21/monster_trojan_steals_millions_of_records/
Second security breach hits Pfizer (16 August 2007)
http://www.theregister.co.uk/2007/08/16/pfizer_security_breach/
Data loss blights US military, Aussie bank, and Fox network (26 July 2007)
http://www.theregister.co.uk/2007/07/26/further_data_loss/
© Copyright 2008