Commentary

George Hulme
 

Connecticut Attorney General Blasts Bank Of New York Mellon

It's happened again. Another backup tape with millions of customers' information has gone missing. The tape was lost on Feb. 27, and the Connecticut authorities want to know more.

It's happened again. Another backup tape with millions of customers' information has gone missing. The tape was lost on Feb. 27, and the Connecticut authorities want to know more.According to a letter from the State of Connecticut's Attorney General, Richard Blumenthal, 10 unencrypted (yes, unencrypted) backup tapes were placed in a truck for "safe" delivery to a secure storage facility. The lock at the back of the truck was busted. And, only nine tapes made it to their planned destination.

Here's what the (unencrypted) tapes contained, according to Attorney General Blumenthal's letter:


More Security Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

BNY representatives informed my office that the information on the tapes contained, at a minimum, Social Security numbers, names and addresses, and possibly bank account numbers and balances.

In the letter, available here, the attorney general asks the bank a series of 12 questions that aim to get to the bottom of this incident, as well as any other possible incidents.

I just have two questions: Why has it taken so long for the loss of this backup tape to become public? Why wasn't the tape encrypted?

Perhaps the tape is just misplaced. Perhaps it fell out of the truck and rolled down a sewer. Perhaps only nine tapes where placed on the truck in the first place. Or maybe, a bad guy busted the lock and grabbed a tape. The broken lock on the truck points to an uncomfortable likelihood that the tape was stolen, and all 4.5 million customers should have been notified right away.

Of course, all of this could have been avoided by scrambling the information on the tape. Of all the things companies can do to protect your information, encrypting backup tapes is one of the most straightforward. The problem is, too few companies, including banks, care enough about your information to take the time, or spend a few extra bucks, to make sure it's managed safely.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links