Showing posts with label Government Laptop Theft. Show all posts
Showing posts with label Government Laptop Theft. Show all posts

Wednesday, 16 September 2009

DuPont Sues Employee for Insider Theft


Many of us think about protecting our data against the strangers of the world who might be trying to find a way to use our information to their benefit. It can be surprising, therefore, when the breach occurs within our company (or circle of friends, family, etc). Unfortunately, DuPont is learning that insider theft is becoming
more and more common.businessman at laptop

The industrial manufacturing company discovered that one of their employees, a senior research chemist, transferred confidential files containing trade secrets from his company-issued laptop to an external hard drive.

Immediately, I couldn't help but wonder why DuPont wouldn't have some sort of alert in place in case someone tried to attach a hard drive to company computers. I was further baffled when I learned that this isn't the first time they've been through this.

After 10 years with DuPont, an employee gathered information from thousands of documents and scientific abstracts. His mission? To sell the information to rival company, Victrex. He ended up being sentenced to 18 months of jail time.

Original Article - http://blog.absolute.com/dupont-sues-employee-for-insider-theft/ 


Thursday, 16 July 2009

Sting nabs sticky-fingered JFK airport workers going through luggage

A sting captured by security cameras nabbed two sticky-fingered airport workers who swiped electronics planted by authorities, officials said. Brian Burton, 27, and Antwon Simmons, 26, stole a laptop and cell phone from the decoy luggage as it moved through Kennedy Airport, Port Authority officials said.

"When air travelers check their luggage with an airline, there is an implicit trust that their bags and their contents will meet them at their destination," said Queens District Attorney Richard Brown. "The defendants are accused of betraying that trust."

Burton, an officer with the Transportation Security Administration, was videotaped July 7 pilfering through the Miami-bound suitcase in an airport screening room while Simmons, a baggage handler, looked on. The thieves also switched the luggage tags, hoping to conceal their handiwork, officials said.

The suitcase was a trap set by the Transportation Security Administration and Delta Air Lines. They stuffed the luggage with a lap top, an iPod and two cell phones, prosecutors said. The pilfering pair - who had been on cops' radar, a source said - took the bait, failing the so-called integrity test.

Burton, of Queens, and Simmons, of Brooklyn, were awaiting arraignment last night on charges of grand larceny, possession of stolen property and falsifying business records.

They face up to four years in prison if convicted.

Monday, 13 July 2009

How to Protect Your Laptop from Theft and Data Loss

Laptops have become one of those devices that is quickly going, and in some cases, already quickly gone from something that only techies or high level business people owned to something that even a poor college student finds a way to afford. This is simply that our lives become wrapped around these objects. Think of the cell phone. Ten to 15 years ago it was again only the techies or important business people that owned a cell phone. Now even elementary school kids have them so parents can be in constant contact when necessary.

We all have had the moment when we though we had misplaced our cell phone. Imagine losing your laptop. Not only is it a fairly significant expense, but think of the data you have on there. You probably keep a file with account numbers, you have your family pictures stored there, maybe music, movies. The list is a long one and an important one.

Therefore, make sure you follow the recommendations in this article on how to protect your laptop.

The convenience of the laptop is obvious. The computing power and versatility are equivalent to most desktop computers. With the advent of wi-fi we can be on the internet almost anywhere and be emailing, chatting, writing, surfing the net or shopping, all anywhere in the world.

Here are some daunting statistics for laptop loss from 2008:

Relevant Data Loss and Data Breach Statistics

* 1 in 10 ...laptop computers will be stolen within the first 12 months of purchase.
* 97% ...of lost and stolen notebooks are never recovered.
* 50% ...of organizations reported laptop theft.
* every 43 seconds ...a computer is reported stolen.
* every 3 days ... an information security breach is reported in the U.S.
* 82% ...of all PC's will be mobile devices by 2008, increasing 4 times as fast as PCs.
* 4,425 ...laptops reported left behind in Chicago taxis during a six month period.
* 56 million ...individuals affected by significant U.S. data security breaches, 2005.
* 1 billion ...PC users expected by 2010, up from 660-670 million today.
* 57% ...of corporate crimes are linked to stolen laptops. The latest crimes of espionage and sabotage are theft of executive personnel devices to access vital financial or personnel data. (data source: www.datarevoke.com)

How Much Does Laptop Loss Cost?:

That completely depends on how you look at it and who is doing the looking....

Personal Laptop:

The actual cost here is the cost of the laptop and if stolen while in the laptop bag (most often this is the case) then you've lost all your accessories as well. Not to mention possibly your wallet, MP3 player, passport (eek!). Obviously the actual cost of items and the intangible loss of items such as wallets, all your stored music, your passport, etc. are vastly different.

Business or Corporate Laptop:

Here the intangible costs can be astronomical. We have heard it on the news more than once and most of us have had it hit us directly with someone in the corporate world losing one or more laptops with critical customer data on it. The cost the hardware is only about $4000, the information carried upon it was could be worth millions..

Of course, to get to valuable proprietary information is not the reason for all laptop thefts some laptop thieves head try to quickly sell the laptop as-is. However, some data indicate that about 10 percent to 15 percent of those laptops are stolen by criminals intent on selling the data.

How to Protect Your Laptop:

With this in mind, what can we do as individuals to prevent our own personal loss?

Laptop Security Cables:

This is one of the lowest cost and one of the most effective deterrents to theft. As with most theft attempts, even a small amount of effort can make a huge difference. For this to work you need to make sure that your laptop is equipped with the appropriate feature to attach a cable. This is called a Universal Security Slot.

It is important to pay attention to what you are attaching the laptop and cable to. You sometimes have to think like a thief. If you really wanted to get that laptop could you? If you answer is yes, then you need to add more security. Consider looping the cable through a hole drilled in the lag of the desk. If you just loop it around the leg than all it takes is some one strong enough to lift the desk enough to slip the cable under the leg and whoosh! your laptop is gone...

Keep Your Laptop Out of Sight:

If you are not with your laptop then it should be secured in a locked drawer or in the possession of someone you trust (for the short trip to the restroom for example). Especially if you are in a public place like an airport, bookstore, or your favorite coffee shop. Never leave your bag alone.

Some laptop cases scream "I have a laptop in here!"

Try to use a carrying case for your laptop that may be a bit beat up or at least not look like it obviously contains a laptop. This may be difficult to do but can be a real effective way to have a thief move on to the next victim without bothering your precious laptop inside your ugly bag.

Monday, 29 June 2009

Another day, another laptop loss...

Yesterday it was a HSE laptop with sensitive financial information on the public. (Don’t forget the HSE has form - with multiple data losses just last year - and has now shown that it has broken its promise to encrypt all laptops containing sensitive personal information.)

Today it’s the turn of Bord Gáis to lose another unencrypted laptop containing bank account and credit card details of 75,000 customers.

We’ve been banging on about this for a while, but it’s worth repeating that in light of these fiascos, a law to warn you that your data has been stolen is long overdue:

At the moment, there is no legal obligation on a body which loses your personal information to notify you. This means that individuals may be unaware that sensitive information such as medical histories or financial records has been lost. It may be, for example, that the first you learn about it is when you go to the ATM and find that your account has been emptied.

What’s being done on this front at the moment? The Minister for Justice has kicked this issue to touch for the time being, setting up a working group to consider whether mandatory reporting should be introduced - and we’ve made submissions to that group. But if you want to see action taken sooner rather than later, now would be a good time to let your TDs (firstname.surname@oireachtas.ie) and MEPs (contact details here) know that you support a right to be warned when your data has been stolen.

Perhaps most importantly, you might want to ask yourself this question - if this is what happens to your financial information, what can you expect to happen to your email and web information if the government is allowed to continue with its plans for data retention?

Monday, 1 June 2009

Data loss firm contract axed

Memory stick
The information contained on a memory stick was not encrypted

A company which lost the details of thousands of criminals held on a computer memory stick has had its £1.5m contract terminated after an inquiry.

Home Secretary Jacqui Smith said PA Consulting had lost the data after it was transferred securely to the firm.

PA Consulting apologised for the loss of data and had accepted its "responsibilities".

The work had now been taken in-house and PA Consulting's other Home Office contracts, worth £8m, are under review.

The Cabinet Office will also launch a review of all contracts signed by the government with private companies to ensure they were "appropriate", said Ms Smith.

"Our contract had stipulated the sort of security provisions that needed to be in place and that had not happened," added the home secretary.

"We are cancelling this contract and we are urgently reviewing the way in which PA Consulting are meeting the requirements of other contracts we have with them.

"Our investigation has demonstrated that while the information was transmitted in an appropriately secure way to PA Consulting and fed to a secure site, it was subsequently downloaded on to an insecure data stick and that data stick was then lost."

Unlocked drawer

She said the memory stick had not been encrypted or "managed properly" and had not been found despite extensive searches.

RECENT LOSSES
Nov 2007: 25m people's child benefit details, held on two discs
Dec 2007: 7,685 Northern Ireland drivers' details
Dec 2007: 3m learner drivers' details lost in US
Jan 2008: 600,000 people's details lost on Navy officer's stolen laptop
June 2008: Six laptops holding 20,000 patients' details stolen from hospital
July 2008: MoD reveals 658 laptops stolen in four years

A risk assessment was being carried out about the data that was missing, alongside the internal inquiry into what had happened, she said.

And no more information was being passed to the firm while the investigation continued and the government was "reviewing the terms of that contract and other contracts" with PA Consulting.

The memory stick contained un-encrypted details about 10,000 prolific offenders as well as names, dates of births and some release date of all 84,000 prisoners in England and Wales - and 33,000 records from the police national computer.

Cancelling the contract will not cost the taxpayer and any expenses incurred will have to be met by PA Consulting, Ms Smith said.

The memory stick contained the details of 84,000 prisoners held in England and Wales.

The device also contained the names, addresses and dates of birth of 30,000 people with six or more convictions in the last year, as well as the names and dates of birth of 10,000 criminals regarded as prolific offenders, from the police national computer.

The loss of data on this project was caused by human failure, a single employee was in breach of PA's well-established information security processes
PA Consulting

It also carried the initials of people on drug treatment programmes.

It was left in an unlocked drawer in an unsecured office at its offices in Victoria, central London.

The loss led to fears prisoners would attempt to claim compensation but Ms Smith reassured MPs that "appropriate measures are in place for individuals seeking information about the data held on them".

Critics say the mistake raises further doubts about the government's controversial ID card project, in which PA Consulting is involved.

Ms Smith said: "The inquiry that we have carried out ... suggests that the most likely thing to have happened was that the data stick was pilfered or lost.

"I think (PA Consulting) recognise that what they have done is against the terms of their contract."

'Apologise unreservedly'

In its first public statement on the data loss incident, a spokesman for PA Consulting said: "The loss of data on this project was caused by human failure, a single employee was in breach of PA's well-established information security processes.

"We deeply regret this human failure and apologise unreservedly to the Home Office."

He said the firm had carried out an examination of all of its government and private sector projects which handle sensitive data.

"Our review has confirmed that, apart from in this isolated incident, we are fully compliant with robust policies and procedures and are achieving high levels of information assurance across all of our work," the spokesman added.

Liberal Democrat home affairs spokesman Tom Brake accused minister of trying to escape criticism for data losses by "making scapegoats out of private companies".

"Barely a week goes by without the government being embroiled in another data cock-up, and yet ministers remain intent on pressing ahead with their Orwellian plans for a national identity register.

"The Government has proved it cannot be trusted with even basic information, let alone with something as intrusive and excessive as the ID cards scheme."

At the weekend, it emerged that another private contractor, EDS, mislaid a computer disc carrying personal details of thousands of employees of the National Offender Management Service in July last year.

Monday, 20 April 2009

Blears PC loss - officials blamed

Hazel Blears
The break-in took place at Hazel Blears Salford office on 14 June

Information on a computer stolen from Communities Secretary Hazel Blears' office had been sent in breach of data security rules, it has emerged.

The Communities and Local Government department admitted its officials had "not fully" complied with guidance on handling sensitive data.

Its top civil servant Peter Housden said "no damage had been done" as the documents were not secret.

Manchester Police are investigating the theft from Ms Blears' Salford office.

The computer contained a combination of constituency and government information relating to defence and extremism.

I have instructed my officials that departmental procedures are now strengthened to ensure this does not happen again
Peter Housden
Communities and Local Government

Mr Housden said in a statement: "It is clear that papers have been sent to Hazel Blears in a way that is not fully consistent with the departmental guidance.

"Thankfully no damage has been done since the documents sent to her were not classified as secret or top secret. And in any event the computer was password protected.

"I have instructed my officials that departmental procedures, guidance, and the awareness and accessibility of that guidance, are now strengthened to ensure this does not happen again.

"I take full responsibility for ensuring this is done."

Confidential document

Department sources suggested that no officials were likely to lose their job over the breach, but did not rule out disciplinary action.

This is the latest in a series of security breaches that have embarrassed the government. Last week a senior Cabinet Office official was suspended for leaving top secret documents on a train.

Another file of documents, including one restricted one, was found on another train last week as well.

The news that a government minister may have been directly responsible for the loss of data relating to extremism is extremely alarming
Dominic Grieve
Shadow home secretary

After Gordon Brown was informed of the theft from Ms Blears' office, he told cabinet ministers to ask their civil servants to remind staff of the importance of enforcing procedures on the treatment of sensitive information.

Shadow home secretary Dominic Grieve called for Parliament to be told "exactly how and why this has occurred".

"The news that a government minister may have been directly responsible for the loss of data relating to extremism is extremely alarming," he said.

The stolen computer is understood to have contained one confidential document relating to the housing market from March this year, as well as other restricted documents.

But the documents did not contain any information that could compromise national security.

They also contained information that shows Cabinet members disagree over the government's proposed planning laws.

'Alarm'

Restricted government documents should not be held on a personal computer.

A government spokesman said the machine contained material from the Department for Communities and Local Government and details relating to her constituency work.

He insisted no personal details were among the departmental information.

"There was a break-in at the constituency office of Hazel Blears on the afternoon of Saturday, 14 June. Hazel was not there at the time, " the spokesman said.

"The thief broke in through a window, triggering the building's security alarm. A PC was stolen. Nothing else was taken.

"We understand the building's security staff arrived within minutes.

"The PC was primarily used for Hazel's constituency business and contained some details of her constituency work."

The spokesman said "none of the departmental material included sensitive personal data about the public or would be of use to criminals".

He added: "The PC did not contain any secret or top secret information and the contents of the PC are protected and clearly this is now subject to a routine police investigation."

Source - BBC News