Feeds

Lost CD may put pension holders in peril

HMRC dodges cryptic question

The essential guide to IT transformation

Thousands of customers of UK insurer Standard Life have been left at risk of fraud after their personal details were lost by HM Revenue & Customs (HMRC).

Data on 15,000 pension policy holders, sent in a CD from HMRC offices in Newcastle to Standard Life's Edinburgh headquarters by courier, never arrived.

The lost disc contained names, national insurance numbers, dates of birth, addresses, and pension data. Information such as this would easily lend itself to abuse by crooks if it fell into the wrong hands. Providing fraudsters were able to read the disc they might be able to apply for loans or credit cards under false names.

News of the loss of the disc, which should have arrived five weeks ago, emerged over the weekend after Standard Life sent out warning letters to its clients. Standard Life's director for customer services, John Gill, told BBC Radio 4's Money Box program: "We have no evidence that the disc has fallen into third party hands and we have also been closely monitoring all the accounts and have seen no indications of any suspicious activity."

UK tax authorities reportedly routinely send confidential data on taxpayers to their pension providers via CD, a procedure that has been found wanting of late. A second CD containing information on customers of an unnamed second insurer has also gone missing, the BBC reports.

HM Revenue has declined to confirm whether the data on the disks was encrypted or not.

This latest in a seemingly never-ending series of security breaches by large organisations on either side of the Atlantic shows the issue is far from confined to lost laptops or leaky database servers. Some organisations have become repeat offenders.

Only last month, for example, HM Revenue lost a laptop containing the personal details of 2,000 people with investment ISAs. In May, Standard Life sent around 300 policy documents to the wrong people.

Security vendors were quick to point to the benefits of encryption in preventing customer information security breaches. "This latest leak shows how easy it is for personal data to go astray, even when being delivered personally," said Nick Lowe, Check Point's regional director for Northern Europe.

"Data needs to be protected wherever it is, whether it's in motion on a CD or laptop computer, or at rest within the company network. Strong encryption really is the only way to achieve this, and the encryption should be automated so that it happens without users' intervention." ®

Next gen security for virtualised datacentres

More from The Register

next story
Ice cream headache as black hat hacks sack Dairy Queen
I scream, you scream, we all scream 'DATA BREACH'!
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
KER-CHING! CryptoWall ransomware scam rakes in $1 MEEELLION
Anatomy of the net's most destructive ransomware threat
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New Snowden leak: How NSA shared 850-billion-plus metadata records
'Federated search' spaffed info all over Five Eyes chums
Three quarters of South Korea popped in online gaming raids
Records used to plunder game items, sold off to low lifes
prev story

Whitepapers

5 things you didn’t know about cloud backup
IT departments are embracing cloud backup, but there’s a lot you need to know before choosing a service provider. Learn all the critical things you need to know.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Backing up Big Data
Solving backup challenges and “protect everything from everywhere,” as we move into the era of big data management and the adoption of BYOD.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?